Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?

⚠ Common exam trap

The trap here is assuming that any ICMP traffic to multiple hosts is a Smurf or flood attack, ignoring the large, high-entropy payloads that indicate tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP tunneling

The correct answer is ICMP tunneling because the traffic pattern shows large, high-entropy payloads in both ICMP echo requests and replies, which is a known method for covert data exfiltration or command-and-control. Normal ICMP traffic uses small, predictable payloads. The other options describe denial-of-service or routing manipulation attacks that do not match the observed bidirectional data exchange.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ICMP redirect attack

    Why it's wrong here

    An ICMP redirect attack involves sending forged ICMP redirect messages to alter a host's routing table, typically with small packets and specific type/code values. The scenario describes echo requests and replies with large payloads, not redirect messages. The high-entropy data in both directions is inconsistent with a redirect attack, which does not carry such payloads.

  • ✗

    Ping flood

    Why it's wrong here

    A ping flood is a denial-of-service attack where a single host sends a massive volume of ICMP echo requests to overwhelm a target. Here, the traffic is not a flood to one target; it is a series of requests to multiple external hosts with large, high-entropy payloads in both directions. The bidirectional data exchange indicates tunneling, not a flood.

  • ✗

    Smurf attack

    Why it's wrong here

    A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing many hosts to reply to the victim. In this scenario, the requests are sent to multiple external hosts individually, not to a broadcast address, and the replies are directed back to the sender, not a spoofed victim. The large payloads and high entropy do not match Smurf characteristics.

  • ✓

    ICMP tunneling

    Why this is correct

    ICMP tunneling encapsulates data within ICMP echo request and reply packets, often using large payloads with high entropy to hide exfiltration or command-and-control traffic. The scenario describes large, non-ASCII, high-entropy payloads in both directions, which is a classic indicator. Normal ping traffic uses small, predictable payloads, so the unusual size and content strongly suggest tunneling.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.