CompTIA Network+ (N10-009)Network SecurityHard

A security analyst detects unusual outbound traffic from several internal servers to an external IP address known for hosting command-and-control (C2) infrastructure. The traffic is highly encrypted and occurs at irregular intervals. Which type of malware is most likely responsible for this activity?

  1. ASpyware
  2. BAdware
  3. CRansomware
  4. DBotnet
Show answer & explanation

Correct answer: D. Botnet

Outbound encrypted traffic to a known C2 server at irregular intervals is a strong indicator of a botnet. Botnet-infected machines communicate with a C2 server to receive commands, often using encryption to evade detection and operating sporadically to blend in.

Why the other options are wrong

  • A. Spyware collects user information and sends it back to an attacker, but the description of 'external IP known for hosting command-and-control (C2) infrastructure' points more specifically to botnet activity.
  • B. Adware typically displays unwanted advertisements and doesn't usually involve C2 communication.
  • C. Ransomware encrypts user data and demands payment, its primary communication is typically for key exchange or payment, not continuous C2 traffic.

Botnet

A network of compromised computers (bots) controlled by a single attacker (bot-herder) via a command-and-control (C2) server, used for malicious activities.

  • Infected machines (bots) communicate with a C2 server for instructions.
  • Often uses encrypted and irregular communication patterns to avoid detection.
  • Can be used for DDoS attacks, spamming, data theft, and more.

Memory trick: Malware talks in different ways; C2 is the bot's secret language.

More Network Security questions