200-201 Network Intrusion Analysis Practice Question
A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?
⚠ Common exam trap
The trap here is assuming that any ICMP traffic to multiple hosts is a Smurf or flood attack, ignoring the large, high-entropy payloads that indicate tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP tunneling
The correct answer is ICMP tunneling because the traffic pattern shows large, high-entropy payloads in both ICMP echo requests and replies, which is a known method for covert data exfiltration or command-and-control. Normal ICMP traffic uses small, predictable payloads. The other options describe denial-of-service or routing manipulation attacks that do not match the observed bidirectional data exchange.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ICMP redirect attack
Why it's wrong here
An ICMP redirect attack involves sending forged ICMP redirect messages to alter a host's routing table, typically with small packets and specific type/code values. The scenario describes echo requests and replies with large payloads, not redirect messages. The high-entropy data in both directions is inconsistent with a redirect attack, which does not carry such payloads.
- ✗
Ping flood
Why it's wrong here
A ping flood is a denial-of-service attack where a single host sends a massive volume of ICMP echo requests to overwhelm a target. Here, the traffic is not a flood to one target; it is a series of requests to multiple external hosts with large, high-entropy payloads in both directions. The bidirectional data exchange indicates tunneling, not a flood.
- ✗
Smurf attack
Why it's wrong here
A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing many hosts to reply to the victim. In this scenario, the requests are sent to multiple external hosts individually, not to a broadcast address, and the replies are directed back to the sender, not a spoofed victim. The large payloads and high entropy do not match Smurf characteristics.
- ✓
ICMP tunneling
Why this is correct
ICMP tunneling encapsulates data within ICMP echo request and reply packets, often using large payloads with high entropy to hide exfiltration or command-and-control traffic. The scenario describes large, non-ASCII, high-entropy payloads in both directions, which is a classic indicator. Normal ping traffic uses small, predictable payloads, so the unusual size and content strongly suggest tunneling.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.