SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard
A security analyst is reviewing network traffic logs for unusual activity. They observe a significant amount of outbound traffic from an internal server to an unknown external IP address on TCP port 443, but the traffic does not appear to be standard HTTPS. Further investigation reveals that the server is communicating with a known malicious domain. Which type of communication is MOST likely occurring?
- APeer-to-peer (P2P) file sharing
- BCommand and Control (C2)
- CDNS exfiltration
- DIntrusion Detection System (IDS) alerts
Show answer & explanationAnswer & explanation
Correct answer: B. Command and Control (C2)
Outbound traffic to an unknown external IP on a common port (like 443) that is not standard for that port's service (not standard HTTPS) and communicating with a 'known malicious domain' is highly indicative of Command and Control (C2) communication. Attackers often use common ports and protocols like HTTPS to blend in with legitimate traffic and evade detection.
Why the other options are wrong
- A. P2P file sharing typically uses a wider range of ports and often involves multiple external connections, not necessarily a single malicious domain in this context.
- C. DNS exfiltration uses DNS queries to send data, usually on UDP port 53, and would manifest differently than 'significant outbound traffic' on TCP 443.
- D. IDS alerts are notifications generated by an IDS, not a type of communication itself. The described activity is what would trigger an IDS alert.
Command and Control (C2) Communication
The communication channel used by an attacker to remotely control compromised systems (bots or implants) within a target network. It's how attackers issue commands and exfiltrate data.
- Often mimics legitimate protocols (HTTP, HTTPS, DNS) to evade detection.
- Can use various ports, frequently common ones like 80, 443, 53.
- Essential for maintaining persistence and achieving attack objectives.
Memory trick: C2 is the Control Channel for Compromised Devices.