Which Logs Identify a Host Compromised by a Command-and-Control Server?
An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)
Community Votes
100% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to prioritize network-telemetry logs for threat correlation, while the common trap is selecting DHCP or authentication logs that lack direct evidence of active C2 communications.
This question evaluates log analysis strategies for detecting and isolating hosts communicating with malicious command-and-control (C2) infrastructure. The candidate community strongly consensus points to Network and Firewall logs as the primary sources for tracing suspicious traffic patterns.
Many candidates incorrectly choose DHCP logs because they associate IP address assignments with specific devices. However, DHCP records only show lease history and do not capture live traffic flows, protocol details, or connection timestamps needed to verify active C2 callbacks.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answers: Network and Firewall Logs
In a command-and-control (C2) incident, identifying the impacted host requires correlating external threat intelligence with internal traffic telemetry. Firewall logs record permit/deny actions, source/destination IPs, ports, and protocols, allowing analysts to pinpoint which internal hosts initiated unauthorized outbound connections to known malicious IPs or domains. Similarly, Network logs, such as NetFlow, sFlow, or router traffic counters, provide comprehensive visibility into bandwidth usage, connection states, and lateral movement patterns across the infrastructure.
Why Other Options Are Incorrect
While DHCP logs map IP addresses to MAC addresses and lease times, they are purely administrative records. They cannot confirm whether a device was actively communicating with a C2 server at a specific time. Authentication logs track login attempts and credential usage, which are valuable for detecting account compromise but insufficient for isolating network-based C2 callbacks without accompanying network telemetry. Application logs reside on individual endpoints and may be deleted, tampered with, or masked by the malware itself, making them unreliable as a primary triage source in broad incident response scenarios.
Community Insights & Exam Context
As noted by multiple candidates, analyzing inbound and outbound traffic at the perimeter (firewall) and core routing layers (network switches/routers) provides the fastest path to containment. The SY0-701 exam heavily emphasizes defensive security operations where network-level visibility takes precedence over host-level forensics during initial incident scoping.
Official Reference
- https://www.comptia.org/certifications/security-plus
- NIST Special Publication 800-61 Rev. 2: Computer Security Incident Handling Guide
- RFC 5424: The Syslog Protocol
- Cisco ASA Firewall Log Analysis Guide
Exam Strategy
When an incident response question asks you to identify affected systems based on external communications, always prioritize logs that capture traffic flows and security boundary enforcement. Eliminate configuration or identity-focused logs unless the scenario explicitly mentions credential theft or endpoint-specific application anomalies.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →