マイアミの運送会社で行われた侵入テスト中、倫理ハッカーのダニエルは、隠されたペイロードを含む偽装メールの添付ファイルを配信しました。従業員によって実行されると、侵入されたワークステーションはダニエルの管理下にあるリモートサーバーと密かに通信を開始します。その後1週間かけて、ダニエルは感染した複数のエンドポイントが同期されたコマンドを受信し、バックグラウンドタスクを同時に実行できること、そして要求に応じて大量のアウトバウンドトラフィックを送信することを確認しました。
この評価でダニエルがシミュレートしている可能性のある悪意のあるコンポーネントの種類はどれですか?
正解:B
The correct answer is B. Botnet Agents because the behavior described matches a command-and-control (C2) driven malware model where multiple compromised systems ("bots" or "zombies") communicate with a remote controller and can be issued coordinated commands. In CEH-aligned malware concepts, a botnet is a collection of infected endpoints under centralized or distributed control. The malicious component installed on each infected workstation is commonly referred to as a bot/bot agent, which "checks in" to a C2 server to receive instructions and execute tasks silently in the background.
Several details strongly indicate botnet agent behavior: the payload is delivered via a disguised email attachment (a common initial infection vector), compromised machines silently communicate outbound to a remote server, and-most importantly-Daniel confirms multiple infected endpoints can receive synchronized commands and carry out actions simultaneously. The example of "sending bursts of outbound traffic on demand" aligns with typical botnet capabilities such as orchestrated DDoS traffic generation, mass scanning, spam sending, credential stuffing, or distributed task execution. The sustained observation "over the following week" also fits a botnet model where infected hosts maintain persistence and periodically beacon to C2 for updates and instructions.
Why the other options do not fit: Spyware primarily focuses on covertly collecting information (keystrokes, screenshots, browsing data) rather than executing synchronized commands across many machines. Scareware relies on alarming messages to trick users into paying or installing unwanted software; it does not describe silent C2 coordination. PUAs are typically unwanted but not necessarily malicious, often installed via bundling and usually lack structured C2 for coordinated remote command execution.
Therefore, the malicious component being simulated is best identified as botnet agents operating under C2 control.