Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A company recently suffered a data breach where sensitive customer information was exfiltrated. The investigation revealed that the attacker gained access through an employee's workstation that was infected with malware. This malware then established a command-and-control (C2) channel to an external server. The security team wants to implement a solution that can detect and prevent such C2 communications by analyzing traffic patterns and known malicious signatures. Which network security technology would be most effective for this purpose?

  1. ALoad Balancer
  2. BNetwork Access Control (NAC)
  3. CIntrusion Detection System (IDS)
  4. DData Loss Prevention (DLP) system
Show answer & explanation

Correct answer: C. Intrusion Detection System (IDS)

An Intrusion Detection System (IDS) is designed to monitor network traffic for suspicious activity and known malicious signatures, making it highly effective at detecting command-and-control (C2) communications and other intrusion attempts.

Why the other options are wrong

  • A. A load balancer distributes traffic, it does not detect or prevent C2 communications.
  • B. NAC controls who can connect to the network, not the content of their traffic once connected.
  • D. DLP focuses on preventing sensitive data from leaving the network, not detecting C2 establishment.

Intrusion Detection System (IDS)

A security technology that monitors network or system activities for malicious activity or policy violations and produces reports to a management station.

  • Primarily focuses on detection, not prevention (unlike IPS).
  • Uses signature-based or anomaly-based detection methods.
  • Can operate on network traffic (NIDS) or host activities (HIDS).

Memory trick: Detectives (IDS/IPS) watch for bad guys, while guards (firewall) block doors.

More Network Security questions