After a series of ueba alerts a companys soc observes an ext - CompTIA CySA+ CSO-003

Question

After a series of UEBA alerts, a company's SOC observes an extended period of suspicious outbound traffic all with the same destination. Which of the following steps of the cyber kill chain has this attack completed?
 

Answers
  1. correct
Explanation

Correct answer: b. Command and Control (C2)

The Command and Control stage occurs after an attacker has successfully exploited a vulnerability on a target system. Once access is gained, the compromised system must maintain communication with the attacker's infrastructure—often referred to as a C2 server—to receive further commands, updates, or to exfiltrate data.

Key signs of C2 activity include:

  • Sustained or periodic outbound traffic from the infected host to the same external destination (especially to suspicious or rarely used IP addresses or domains).
  • Encrypted or obfuscated communications intended to bypass detection.
  • Use of non-standard ports or protocols.

This stage is crucial for attackers to maintain control over their foothold in the network and conduct further malicious activities.

Why the other choices are incorrect:

  • Weaponization: The weaponization phase is part of the pre-attack preparation. In this stage, the attacker takes a known vulnerability and pairs it with a crafted exploit and a delivery method (like a malicious macro or a booby-trapped document). This occurs entirely on the attacker's side and does not generate any network traffic, especially not from the target system. Therefore, extended outbound communication cannot be associated with this phase.
  • Reconnaissance: Reconnaissance involves the attacker researching and gathering information about a potential target—such as IP addresses, domain names, employee names, or technology stack—to identify possible vulnerabilities. This stage is typically passive and occurs before any direct interaction with the target network. Because no system has been compromised at this point, there would be no internal or outbound traffic from the target system to observe.
  • Exploitation: Exploitation is the initial point of compromise, where the attacker executes malicious code on the target system by taking advantage of a vulnerability. This may include triggering a buffer overflow, executing a macro, or exploiting an unpatched service. While exploitation might cause some initial communication (like a callback), it is generally a short-lived, one-time event. It does not involve the ongoing or periodic outbound communication characteristic of the C2 phase.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered