200-201 Network Intrusion Analysis Practice Question
A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload sizes and no corresponding echo replies. The analyst suspects the host is being used for reconnaissance or data exfiltration. Which characteristic of the ICMP traffic would most strongly indicate that it is being used for data exfiltration rather than simple reconnaissance?
⚠ Common exam trap
The trap here is focusing on the volume or rate of ICMP traffic, when the payload content and encoding are the definitive indicators of exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ICMP packets contain non-standard payload data that is base64-encoded and varies in length.
The presence of non-standard, base64-encoded payload data that varies in length is a classic sign of ICMP tunneling for data exfiltration. Normal ping requests have predictable payloads, often just a repeating pattern or timestamp. When ICMP is used as a covert channel, the payload carries encoded stolen data, making the traffic anomalous. The other options describe patterns more consistent with reconnaissance or benign monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The payload sizes are consistent and small, matching standard ping requests.
Why it's wrong here
Consistent, small payloads are typical of normal ping sweeps used for reconnaissance. Data exfiltration usually requires larger or variable payloads to carry meaningful data, so this pattern would suggest scanning rather than exfiltration. Therefore, this characteristic does not indicate exfiltration.
- ✓
The ICMP packets contain non-standard payload data that is base64-encoded and varies in length.
Why this is correct
ICMP tunneling for exfiltration often embeds encoded data in the payload, such as base64 strings, which are not present in normal ping requests. The varying length and non-standard content indicate that the ICMP echo requests are carrying hidden data rather than simply testing connectivity. This is a strong indicator of exfiltration or covert channel use.
- ✗
The source IP address is spoofed to match the destination IP address.
Why it's wrong here
Spoofing the source to match the destination would be unusual and would likely cause the echo reply to be sent to the destination itself, not the attacker. While spoofing can be used in some attacks, it is not a typical characteristic of ICMP exfiltration, which usually requires a bidirectional channel to receive data. Thus, this does not indicate exfiltration.
- ✗
The ICMP echo requests are sent at a constant rate of one per second to a single external IP.
Why it's wrong here
A constant rate to a single IP is more indicative of a heartbeat or keep-alive mechanism, not necessarily data exfiltration. Exfiltration often involves variable timing and multiple destinations, or at least variable payloads. A steady ping to one host could be benign monitoring, so this characteristic alone does not strongly indicate exfiltration.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.