Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst is reviewing NetFlow records and notices a persistent, low-volume communication pattern between an internal host and an external IP address. The communication consists of small, encrypted packets occurring at regular, fixed intervals (e.g., every 60 seconds). This pattern is inconsistent with normal user activity or known applications. What does this communication pattern most likely indicate?
- ANormal system update traffic
- BLegitimate P2P file sharing
- CInteractive remote desktop session
- DMalware beaconing
Show answer & explanationAnswer & explanation
Correct answer: D. Malware beaconing
Malware beaconing is a common technique where compromised hosts periodically send small packets (beacons) to a command and control (C2) server to indicate they are still active and ready for instructions. The 'low-volume, encrypted, at regular fixed intervals' pattern is a classic signature of beaconing, designed to evade detection by blending with background noise.
Why the other options are wrong
- A. System updates typically involve larger, less regular data transfers, not small, fixed-interval packets.
- B. P2P file sharing usually involves high-volume, bursty traffic with many different peers, not low-volume, fixed-interval communication to a single external IP.
- C. Interactive remote desktop sessions generate variable traffic based on user activity, not fixed-interval, low-volume packets.
Malware Beaconing
A technique used by malware where a compromised host periodically sends small, often encrypted, communication packets to its command and control (C2) server.
- Indicates the host is still active and connected to the C2.
- Characterized by regular, fixed intervals and low data volume.
- Often uses common ports (e.g., 80, 443) or DNS to blend in.
Memory trick: Malware calls home like a robot checking in.