A single licensing-counter kiosk at the city's DMV-style office is compromised and phones home. Days later, dozens of similar kiosks report to the same controller. How should the analyst label the one host versus the coordinated collection?
Select an answer to reveal the explanation.
Short Explanation
One puppet is a bot; a whole puppet show answering the same puppeteer is a botnet. The first infected licensing kiosk is the puppet, and the fleet calling one controller is the show — do not swap those labels or call the kiosk the C2 server.
Full Explanation
A bot is a single compromised host under remote direction, while a botnet is the coordinated collection of such hosts reporting to one controller. Command-and-control is the channel or infrastructure, not the kiosk itself, and zero trust is a verification model, not an infected fleet. APT and social engineering name adversary class and human manipulation, not the bot-versus-botnet distinction. Civic analysts should keep the terms straight so ES notables, threat intel, and takedown scoping describe one host or the whole licensing-kiosk collection.