Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 6 Question 4 Discussion

Refer to the exhibit.A security analyst receives an alert from Cisco Secure Network Analytics (formerly StealthWatch) with the C2 category. Which information aids the investigation?
C) Host 10.201.3.99 is attempting to contact the C2 server to retrieve the payload.
A) The number of packets shows that a C2 communication occurred.
B) IP address 10.201.3.99 is a C2 server.
D) The payload describes the address of the zombie endpoint.

Cisco 300-220 Exam - Topic 6 Question 4 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 4
Topic #: 6
[All 300-220 Questions]

Refer to the exhibit.

A security analyst receives an alert from Cisco Secure Network Analytics (formerly StealthWatch) with the C2 category. Which information aids the investigation?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C. Host 10.201.3.99 is attempting to contact the C2 server to retrieve the payload.

Cisco Secure Network Analytics (Stealthwatch) detects Command-and-Control (C2) activity by analyzing network behavior, not by relying solely on known malicious indicators. In the exhibit, the critical investigative clue is the HTTP payload containing a suspicious external URL, which strongly suggests outbound communication from an internal host to an external command-and-control infrastructure.

The internal IP address 10.201.3.99 belongs to a workstation group (''Desktops''), indicating it is an internal endpoint, not a C2 server. This immediately rules out option B. Instead, the endpoint is acting as a compromised host (zombie) attempting to reach a remote server controlled by an attacker. This outbound beaconing behavior is a classic hallmark of C2 communication.

Option A is incorrect because packet count alone does not confirm C2 activity. C2 traffic is often low-and-slow, intentionally designed to blend in with normal traffic patterns. Option D is also incorrect because the payload does not describe the zombie endpoint; rather, it shows a remote URL, which is likely part of malware staging or command retrieval.

From a threat hunting and SOC perspective, the most valuable information is directionality and intent:

Internal host external suspicious domain

HTTP-based communication over an unusual port

Low data volume consistent with beaconing or payload retrieval

This aligns with MITRE ATT&CK -- Command and Control (TA0011) techniques such as Application Layer Protocols (T1071). Identifying which internal host is reaching out---and why---is essential for containment, endpoint isolation, and scope expansion.

Professionally, this insight enables the analyst to:

Quarantine host 10.201.3.99

Pivot to EDR telemetry on that endpoint

Block the external domain or IP

Hunt for similar beaconing patterns across the environment

In summary, the investigation is aided most by understanding that an internal host is actively communicating with a C2 server, making Option C the correct and operationally meaningful answer.


Contribute your Thoughts:

0/2000 characters
Marla
1 month ago
But A is also important. It confirms that communication happened.
upvoted 0 times
...
Nikita
2 months ago
I agree, C is the best choice. It indicates a direct attempt to connect.
upvoted 0 times
...
Julian
2 months ago
I think option C is crucial. It shows active communication.
upvoted 0 times
...
Buddy
2 months ago
Wait, how do we know 10.201.3.99 is really a C2 server? Need more proof!
upvoted 0 times
...
Paulene
2 months ago
D) The payload describes the address of the zombie endpoint? Sounds suspicious...
upvoted 0 times
...
Bernardine
2 months ago
C) Host 10.201.3.99 is attempting to contact the C2 server to retrieve the payload. Makes sense!
upvoted 0 times
...
Joseph
4 months ago
A) The number of packets shows that a C2 communication occurred. Definitely relevant.
upvoted 0 times
...
Howard
4 months ago
B) IP address 10.201.3.99 is a C2 server. That's key info!
upvoted 0 times
...
Eric
5 months ago
Option D sounds relevant too, but I can't recall if the payload details are always necessary for the investigation.
upvoted 0 times
...
Gracia
5 months ago
I'm a bit confused about option C. Is it common for hosts to contact C2 servers for payloads? I feel like we practiced something similar.
upvoted 0 times
...
Percy
5 months ago
I think option B is pretty clear-cut since identifying a known C2 server is crucial, right?
upvoted 0 times
...
Nickolas
5 months ago
I remember we discussed how the number of packets can indicate suspicious activity, but I'm not sure if that's enough for a solid investigation.
upvoted 0 times
...

Save Cancel