Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A company recently suffered a data breach where sensitive customer information was exfiltrated. The investigation revealed that the attacker gained access through an employee's workstation that was infected with malware. This malware then established a command-and-control (C2) channel to an external server. The security team wants to implement a solution that can detect and prevent such C2 communications by analyzing traffic patterns and known malicious signatures. Which network security technology would be most effective for this purpose?
- ALoad Balancer
- BNetwork Access Control (NAC)
- CIntrusion Detection System (IDS)
- DData Loss Prevention (DLP) system
Show answer & explanationAnswer & explanation
Correct answer: C. Intrusion Detection System (IDS)
An Intrusion Detection System (IDS) is designed to monitor network traffic for suspicious activity and known malicious signatures, making it highly effective at detecting command-and-control (C2) communications and other intrusion attempts.
Why the other options are wrong
- A. A load balancer distributes traffic, it does not detect or prevent C2 communications.
- B. NAC controls who can connect to the network, not the content of their traffic once connected.
- D. DLP focuses on preventing sensitive data from leaving the network, not detecting C2 establishment.
Intrusion Detection System (IDS)
A security technology that monitors network or system activities for malicious activity or policy violations and produces reports to a management station.
- Primarily focuses on detection, not prevention (unlike IPS).
- Uses signature-based or anomaly-based detection methods.
- Can operate on network traffic (NIDS) or host activities (HIDS).
Memory trick: Detectives (IDS/IPS) watch for bad guys, while guards (firewall) block doors.