GCIH Command and Control Detection Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 15, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. Which log source is most valuable for detecting lateral movement associated with C2 activity?

Submit
Please wait...
About This Quiz
GCIH Command and Control Detection Quiz - Quiz

This quiz evaluates your ability to identify and detect command and control (C2) communications used by attackers to maintain persistent access to compromised systems. You'll assess network indicators, malware behavior patterns, and defensive techniques essential for incident response and threat hunting in real-world environments.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Which of the following best describes 'command injection' in the context of C2 operations?

Submit

3. In incident response, what is the primary benefit of identifying C2 infrastructure early?

Submit

4. Which network-based indicator suggests potential C2 communication?

Submit

5. What is the primary purpose of 'domain generation algorithms' (DGA) in C2 infrastructure?

Submit

6. Which analysis method involves executing suspicious files in an isolated environment to observe C2 behavior?

Submit

7. In C2 detection, what does 'exfiltration' typically refer to?

Submit

8. Which of the following is a characteristic of 'covert channels' used in C2 communications?

Submit

9. What is the primary advantage of using SIEM tools for C2 detection?

Submit

10. In threat hunting, what does 'YARA rule' primarily help detect?

Submit

11. Which network protocol is commonly abused by attackers for command and control due to its legitimate use and difficulty in filtering?

Submit

12. What is a 'proxy chain' in the context of C2 infrastructure?

Submit

13. Which of the following best describes 'DNS tunneling' as a C2 technique?

Submit

14. In C2 detection, what is the significance of analyzing SSL/TLS certificates on suspicious connections?

Submit

15. Which tool is commonly used for passive DNS monitoring to detect C2 communications?

Submit

16. What is a 'fast flux' network in the context of C2 infrastructure?

Submit

17. Which analysis method involves monitoring network traffic to identify C2 communications by examining flow patterns?

Submit

18. In the context of C2 detection, what does 'dead drop' refer to?

Submit

19. Which of the following is a common indicator of compromise (IOC) for detecting C2 activity?

Submit

20. What is the primary characteristic of a beaconing pattern in C2 communications?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Which log source is most valuable for detecting lateral movement...
Which of the following best describes 'command injection' in the...
In incident response, what is the primary benefit of identifying C2...
Which network-based indicator suggests potential C2 communication?
What is the primary purpose of 'domain generation algorithms' (DGA) in...
Which analysis method involves executing suspicious files in an...
In C2 detection, what does 'exfiltration' typically refer to?
Which of the following is a characteristic of 'covert channels' used...
What is the primary advantage of using SIEM tools for C2 detection?
In threat hunting, what does 'YARA rule' primarily help detect?
Which network protocol is commonly abused by attackers for command and...
What is a 'proxy chain' in the context of C2 infrastructure?
Which of the following best describes 'DNS tunneling' as a C2...
In C2 detection, what is the significance of analyzing SSL/TLS...
Which tool is commonly used for passive DNS monitoring to detect C2...
What is a 'fast flux' network in the context of C2 infrastructure?
Which analysis method involves monitoring network traffic to identify...
In the context of C2 detection, what does 'dead drop' refer to?
Which of the following is a common indicator of compromise (IOC) for...
What is the primary characteristic of a beaconing pattern in C2...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!