CompTIA Network+ (N10-009)Network SecurityHard
A security analyst detects unusual outbound traffic from several internal servers to an external IP address known for hosting command-and-control (C2) infrastructure. The traffic is highly encrypted and occurs at irregular intervals. Which type of malware is most likely responsible for this activity?
- ASpyware
- BAdware
- CRansomware
- DBotnet
Show answer & explanationAnswer & explanation
Correct answer: D. Botnet
Outbound encrypted traffic to a known C2 server at irregular intervals is a strong indicator of a botnet. Botnet-infected machines communicate with a C2 server to receive commands, often using encryption to evade detection and operating sporadically to blend in.
Why the other options are wrong
- A. Spyware collects user information and sends it back to an attacker, but the description of 'external IP known for hosting command-and-control (C2) infrastructure' points more specifically to botnet activity.
- B. Adware typically displays unwanted advertisements and doesn't usually involve C2 communication.
- C. Ransomware encrypts user data and demands payment, its primary communication is typically for key exchange or payment, not continuous C2 traffic.
Botnet
A network of compromised computers (bots) controlled by a single attacker (bot-herder) via a command-and-control (C2) server, used for malicious activities.
- Infected machines (bots) communicate with a C2 server for instructions.
- Often uses encrypted and irregular communication patterns to avoid detection.
- Can be used for DDoS attacks, spamming, data theft, and more.
Memory trick: Malware talks in different ways; C2 is the bot's secret language.