Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is investigating a suspected malware infection on a host. Network forensic analysis shows a persistent connection to an external IP address, with small, periodic data transfers. The external IP address resolves to a domain with a suspicious, randomly generated subdomain. No legitimate application on the host is known to communicate with this domain. What does this pattern of communication most strongly suggest?

  1. AThe host is performing legitimate software updates.
  2. BThe host is participating in a peer-to-peer file-sharing network.
  3. CThe host is experiencing a denial-of-service (DoS) attack.
  4. DThe host is part of a botnet's command and control (C2) infrastructure.
Show answer & explanation

Correct answer: D. The host is part of a botnet's command and control (C2) infrastructure.

Persistent connections with small, periodic data transfers to suspicious, randomly generated domains are classic indicators of a botnet's command and control (C2) communication, where the bot receives instructions and sends back status updates.

Why the other options are wrong

  • A. Software updates typically involve larger, less frequent data transfers to known, legitimate vendor domains.
  • B. P2P file sharing involves connections to many different peers, often with large, continuous data transfers, not small, periodic ones to a single external IP.
  • C. A DoS attack would manifest as a flood of outbound traffic from the infected host, not small, periodic transfers, or as inbound traffic overwhelming the host.

Botnet C2 Communication

The communication channel between a botnet's command and control (C2) server and its compromised 'bot' clients, often characterized by persistent, low-volume, periodic traffic to suspicious or dynamically generated domains.

  • Uses various protocols (HTTP, DNS, IRC)
  • Often employs Domain Generation Algorithms (DGAs)
  • Periodically 'phones home' for instructions

Memory trick: Bots Talk Quietly, Regularly, Randomly to Control.

More Network Intrusion Analysis questions