Courseiva

200-201 Network Intrusion Analysis Practice Question

A security analyst observes repeated ICMP port unreachable responses from a target host. The source IP is sending packets to multiple UDP ports. Which type of scan is most likely being performed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

UDP scan

UDP scans elicit ICMP port unreachable messages from closed ports; open ports typically do not respond.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP SYN scan

    Why it's wrong here

    A TCP SYN scan elicits SYN-ACK or RST responses from TCP ports, not ICMP port unreachable messages from UDP probes. It tempts because SYN scanning is the common stealth technique, and it is the right answer when the observed replies come from TCP ports rather than UDP.

  • ✓

    UDP scan

    Why this is correct

    A UDP scan sends packets to many UDP ports; closed ports return ICMP port unreachable messages, exactly matching the observed responses. This distinguishes it from TCP-based scans, which rely on SYN, ACK or RST behaviour rather than ICMP errors.

  • ✗

    TCP connect scan

    Why it's wrong here

    A TCP connect scan completes full TCP handshakes and yields TCP responses, not ICMP port unreachable messages triggered by UDP probes. It tempts because connect scanning is used when raw-socket privileges are unavailable, and it is correct when the target's replies are TCP-based.

  • ✗

    Ping sweep

    Why it's wrong here

    A ping sweep sends ICMP echo requests to map live hosts, so it produces echo replies, not port unreachable messages. The repeated ICMP port unreachable responses to varied UDP ports indicate closed ports on a live target, characteristic of a UDP scan. Ping sweeps suit host discovery across subnets, not port enumeration.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.