312-50 exam dumps

312-50 practice question 230 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 230

Single answer▪ Botnets

During an internal assessment, a security team suspects that several Windows workstations have been recruited into a botnet. The hosts are not showing obvious malware pop-ups, but network monitoring reveals periodic outbound connections to many changing IP addresses over common service ports. Management wants the team to identify likely bot-infected systems without disrupting business operations. Which action would provide the most reliable evidence that the hosts are participating in a botnet command-and-control infrastructure while minimizing impact on production systems?

  1. A

    Correlate endpoint process and persistence artifacts with network telemetry to identify repeated beaconing patterns, suspicious scheduled tasks/services, and communication with known malicious or algorithmically generated domains

  2. B

    Block all outbound traffic from the suspected subnet immediately and treat any user complaint about lost connectivity as confirmation that the machines were bot-infected

  3. C

    Run aggressive password spraying against the suspected workstations to see whether a botnet operator changed local administrator credentials

  4. D

    Look only for a single hard-coded command-and-control IP address in firewall logs, because modern botnets typically rely on one stable server for control

Show answer and explanation

Correct answer: A

Explanation

In CEH-style scenarios, the best answer usually reflects a practical investigation workflow that balances evidence quality with operational impact. Botnets commonly attempt to maintain persistence on endpoints while communicating with command-and-control infrastructure using periodic beaconing, fallback domains, encrypted channels, peer-to-peer mechanisms, or rapidly changing IP addresses. Because of this, analysts should correlate host artifacts with network telemetry rather than rely on a single IOC. This aligns with incident handling and malware analysis best practices promoted by sources such as NIST SP 800-61 (Computer Security Incident Handling Guide) and operational guidance from CISA and major threat intelligence programs, which emphasize validating suspicious network behavior with endpoint evidence before broad containment when possible.

  • A. Correct.

    Correct. Botnet detection in real environments is strongest when host-based evidence is combined with network-based evidence. Repeated low-volume beaconing, unusual persistence mechanisms such as scheduled tasks or rogue services, suspicious child processes, and connections to known malicious infrastructure or domains generated via DGAs are common botnet indicators. This approach is far less disruptive than blanket containment and provides defensible evidence before taking remediation actions.

  • B. Incorrect.

    Incorrect. Immediate network isolation may sometimes be necessary during active incident response, but using business disruption as the primary detection method is not reliable evidence of botnet activity. Many legitimate business applications would also fail if outbound traffic were blocked. This option confuses containment with identification.

  • C. Incorrect.

    Incorrect. Password spraying is a credential attack technique and is unrelated to verifying whether endpoints are participating in a botnet. It would create unnecessary risk, generate noise, and could violate rules of engagement. Bot infections are typically confirmed through malware behavior, persistence, and command-and-control communication patterns, not by testing administrator password changes.

  • D. Incorrect.

    Incorrect. This reflects an outdated view of botnet architecture. Many modern botnets use resilient infrastructure such as DGAs, fast-flux hosting, peer-to-peer communication, rotating C2 nodes, or use common cloud and web services to blend in. Looking for only one static C2 IP is likely to miss compromised hosts.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam