After malware executes on a city clerk workstation, the host opens a periodic encrypted session to an attacker-controlled VPS and waits for instructions. Which term describes that ongoing remote channel?
Select an answer to reveal the explanation.
Short Explanation
That quiet, regular call to the VPS is the walkie-talkie, not the stolen filing cabinet. C2 is the attacker's ongoing remote channel — check-ins, tasking, keep-alive. A one-shot data dump is exfil; a firmware vendor swap is supply chain; neither is this beacon.
Full Explanation
Command-and-control is the attacker's ongoing remote channel for tasking a compromised host. A periodic encrypted session from a clerk PC to a VPS matches C2, not a completed exfiltration burst, a supply-chain implant in hardware, or a zero-trust access policy. Defense Analyst objective 2.2 lists C2 as a distinct term because later stages (theft, ransomware, lateral movement) ride that channel. Civic SOC analysts should hunt the beacon in proxy, DNS, and firewall data and treat it as live attacker presence, not as a finished file copy.