Botnet Protection targets command-and-control behavior, including known C2 destinations, suspicious command traffic, and unknown C2 patterns detected through analytics or AI/ML. IPS and YARA-style content analysis are used to identify C2-like traffic and malicious patterns, not general malware categories alone. Option A (Command and Control Traffic) is correct because Command and Control traffic is the botnet behavior being protected against.
Why the other options are incorrect:
B. Ransomware: Ransomware encrypts or extorts data after compromise. It is not the callback/C2 category for outbound spyware communication.
C. Trojans: Trojans disguise malicious code as legitimate software. Spyware callback protection targets outbound communication from spyware to its controller.
D. Adware/Spyware Protection: Adware/spyware protection is a broad category. The tested feature is the specific spyware callback protection control.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit