During a network forensic investigation, an examiner notices beaconing behavior in firewall logs โ periodic outbound connections to the same external IP at regular intervals. This is most consistent with which threat?
-
A
A scheduled software update process only
-
B
Malware maintaining a command-and-control (C2) channel
-
C
A misconfigured NTP server
-
D
Normal web browsing patterns