Which Logs Identify a Host Compromised by a Command-and-Control Server?

An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)

  1. Application
  2. Authentication
  3. DHCP
  4. Network Source Reference Answer
  5. Firewall Source Reference Answer

Community Votes

DE
100%

100% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to prioritize network-telemetry logs for threat correlation, while the common trap is selecting DHCP or authentication logs that lack direct evidence of active C2 communications.

This question evaluates log analysis strategies for detecting and isolating hosts communicating with malicious command-and-control (C2) infrastructure. The candidate community strongly consensus points to Network and Firewall logs as the primary sources for tracing suspicious traffic patterns.

Many candidates incorrectly choose DHCP logs because they associate IP address assignments with specific devices. However, DHCP records only show lease history and do not capture live traffic flows, protocol details, or connection timestamps needed to verify active C2 callbacks.

Community Discussion (10 comments)

Shaman73 👍 11 Selected: DE
D. Network E. Firewall
VincentvdS 👍 1 Selected: DE
n the context of a command-and-control (C2C) server, analyzing network and firewall logs is more effective for identifying the impacted host. These logs provide detailed information about network traffic, including connections to and from the C2C server, which can help pinpoint the affected devices. The two most relevant logs to analyze in this scenario would be: D. Network Network logs can provide insights into the traffic patterns and connections related to the C2C server. E. Firewall Firewall logs can help identify any unusual or unauthorized connections to the C2C server, aiding in the identification of the impacted host.
Aces155 👍 1 Selected: CD
Bing copilot is saying C and D. The best two logs to analyze for identifying the impacted host in a command-and-control incident would be: Network logs: These provide detailed information about network traffic, including connections to and from the command-and-control server. DHCP logs: These help map IP addresses to specific devices at given times, which is crucial for identifying the impacted host. While firewall logs are valuable for security information, network and DHCP logs together provide the most comprehensive data needed to pinpoint the specific host involved.
41c27e6 👍 2 Selected: DE
Network Logs (D): Network logs are crucial for identifying communication between the compromised host and the command-and-control server. These logs will typically include details of network traffic, including IP addresses, ports, protocols, and patterns of communication. By analyzing network logs, you can track outbound connections that may have been initiated by the infected host to communicate with the command-and-control server. Firewall Logs (E): Firewall logs are useful for identifying inbound and outbound traffic that is blocked or allowed by the firewall. They can help pinpoint suspicious traffic patterns, such as attempts to connect to known malicious IP addresses (such as the command-and-control server). Firewall logs will also show if the infected host tried to bypass any restrictions to communicate with external servers.
Exam_Prep221 👍 1 Selected: CE
DHCP logs: Identify which device was assigned the IP address communicating with the C2 server. Firewall logs: Show network traffic between the impacted host and the C2 server.
c7b3ff0 👍 1 Selected: BE
Since this is specifically asking about identifying the impacted host, I chose B and E. B. Authentication - This log helps identify any unauthorized access or unusual login attempts related to compromised hosts. E. Firewall - provide insights into incoming and outgoing traffic patterns, detecting comms with the C2 server to help identify the affected host.
dbrowndiver 👍 2 Selected: CE
C. DHCP and E. Firewall logs are the correct answers because they provide essential information to trace network communications and identify the specific host(s) impacted by the command-and-control server connection. Firewall logs help pinpoint unusual outbound connections, such as those from internal hosts to a suspicious external server, thus identifying potential breaches. DHCP logs map IP addresses to devices, while firewall logs reveal the network traffic patterns, making them both crucial for this analysis. DHCP logs are crucial for linking IP addresses seen in network activity to actual devices, especially in dynamic environments where IP addresses frequently change.
101e7ca 👍 4 Selected: DE
"command-and-control server" is the problem, attacker has accessed the network and taken control of a machine. We should check the inbound and outbound traffic logs. These will be on the Router(Network) and network Firewall.
Bimbo_12 👍 3 Selected: DE
To identify the impacted host in a cybersecurity incident involving a command-and-control server, the most relevant logs to analyze would be: C. DHCP and E. Firewall : Firewall logs capture network traffic and can show which internal hosts communicated with external IP addresses, including the command-and-control server. By analyzing firewall logs, you can identify the internal IP addresses that initiated or received communication with the command-and-control server, helping to pinpoint the impacted host. If you have already identified suspicious network traffic (e.g., connections to a C2 server) in firewall or network logs, the next step is often to determine which device was responsible for that traffic. DHCP logs are necessary for this step because they map IP addresses to specific devices. Without this mapping, knowing the IP address alone is insufficient, especially in environments where IP addresses are dynamically assigned. By consulting DHCP logs, you can quickly identify the physical or virtual device behind the suspicious activity.
cdsu 👍 2
Answer: C. DHCP E. Firewall C: Impacted host. To trace back any suspicious network activity to a specific device E: Firewall logs contain records of all incoming and outgoing traffic

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Correct Answers: Network and Firewall Logs

In a command-and-control (C2) incident, identifying the impacted host requires correlating external threat intelligence with internal traffic telemetry. Firewall logs record permit/deny actions, source/destination IPs, ports, and protocols, allowing analysts to pinpoint which internal hosts initiated unauthorized outbound connections to known malicious IPs or domains. Similarly, Network logs, such as NetFlow, sFlow, or router traffic counters, provide comprehensive visibility into bandwidth usage, connection states, and lateral movement patterns across the infrastructure.

Why Other Options Are Incorrect

While DHCP logs map IP addresses to MAC addresses and lease times, they are purely administrative records. They cannot confirm whether a device was actively communicating with a C2 server at a specific time. Authentication logs track login attempts and credential usage, which are valuable for detecting account compromise but insufficient for isolating network-based C2 callbacks without accompanying network telemetry. Application logs reside on individual endpoints and may be deleted, tampered with, or masked by the malware itself, making them unreliable as a primary triage source in broad incident response scenarios.

Community Insights & Exam Context

As noted by multiple candidates, analyzing inbound and outbound traffic at the perimeter (firewall) and core routing layers (network switches/routers) provides the fastest path to containment. The SY0-701 exam heavily emphasizes defensive security operations where network-level visibility takes precedence over host-level forensics during initial incident scoping.

Official Reference

Exam Strategy

When an incident response question asks you to identify affected systems based on external communications, always prioritize logs that capture traffic flows and security boundary enforcement. Eliminate configuration or identity-focused logs unless the scenario explicitly mentions credential theft or endpoint-specific application anomalies.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide