312-50 exam dumps

312-50 practice question 231 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 231

Single answer▪ Botnets

During an authorized internal assessment, you discover that several employee workstations are making periodic outbound HTTPS connections to random-looking domains generated every few hours. Endpoint logs show a suspicious process maintaining persistence and receiving small encrypted task updates. The SOC suspects these hosts are part of a botnet using a domain generation algorithm (DGA) for command-and-control (C2) resilience. Which action would be the MOST effective next step to validate the botnet’s C2 mechanism without unnecessarily disrupting business operations?

  1. A

    Block all outbound HTTPS traffic at the perimeter firewall and wait to see which systems generate user complaints

  2. B

    Perform DNS sinkholing or controlled internal redirection for the suspected DGA domains and monitor which hosts attempt to resolve or connect to them

  3. C

    Delete the suspicious process from one affected host immediately and assume the remaining hosts will stop beaconing after the next group policy refresh

  4. D

    Reimage all suspected endpoints at once before collecting any network indicators to prevent further botnet communication

Show answer and explanation

Correct answer: B

Explanation

Botnets commonly use resilient C2 techniques such as DGAs, fast-flux, encrypted channels, and fallback communication paths to avoid simple blocklisting. In this scenario, the best next step is to validate the DGA-based C2 mechanism in a controlled way by using DNS sinkholing or redirection and monitoring affected hosts. This approach aligns with practical incident response and threat hunting methods: confirm the behavior, identify all compromised systems, collect indicators of compromise, and then move into containment and eradication. Broad controls such as blocking all HTTPS are too disruptive and do not specifically test the hypothesis. Likewise, deleting malware or reimaging systems too early can remove evidence and hinder scoping. Best-practice guidance from organizations such as NIST, including incident response lifecycle principles in SP 800-61, supports preserving evidence, analyzing indicators, and using measured containment strategies before full remediation.

  • A. Incorrect.

    This is not the most effective validation step. Blocking all outbound HTTPS is overly disruptive in most enterprise environments because legitimate business applications depend on TLS/HTTPS. It may reduce visible C2 traffic, but it does not specifically validate the suspected DGA-based mechanism and creates significant operational impact. A common misconception is that broad egress blocking is the fastest way to confirm malware activity; in practice, targeted containment and monitoring are preferred when possible.

  • B. Correct.

    This is correct. DNS sinkholing or controlled redirection is a well-established technique for validating suspected botnet C2 behavior, especially when DGA activity is suspected. By redirecting or sinkholing the generated domains to infrastructure you control, you can identify infected hosts attempting resolution or connection, observe beaconing patterns, and gather indicators without broadly interrupting normal business traffic. This method is commonly used in incident response and threat hunting to confirm compromised systems and map the scope of infection.

  • C. Incorrect.

    This is incorrect because deleting the process from a single host is not a reliable validation method and may destroy evidence needed for analysis. Bot malware often uses multiple persistence mechanisms, scheduled tasks, services, registry run keys, or secondary loaders. Removing one process on one system does not confirm how the broader botnet communicates, nor does it prove the remaining hosts are no longer compromised. The reference to group policy refresh reflects a misunderstanding of Windows administration and has no direct relation to botnet C2 eradication.

  • D. Incorrect.

    This is incorrect as an immediate first step for validation. While reimaging may eventually be appropriate for eradication, doing so before collecting network indicators, DNS artifacts, and host evidence can eliminate valuable forensic data and make it harder to understand the C2 infrastructure, infection vector, and full scope of compromise. In incident handling, validation and scoping typically precede large-scale remediation unless there is an acute safety or business-critical reason to isolate immediately.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam