Courseiva
Network Intrusion Analysis →mediumMultiple Select

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is triaging an alert from a network sensor indicating that an internal host may be performing host discovery on the local subnet. The analyst wants to identify active hosts without generating TCP connections. Which two techniques should the analyst expect to see in the packet capture that are consistent with this goal? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any probe which elicits a response counts as host discovery, when the requirement specifically excludes TCP connections and targets host liveness rather than services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP echo requests sent to each address in the subnet range

ICMP echo requests and ARP requests are both connectionless techniques that confirm host liveness without establishing TCP sessions. ICMP echo requests work across routed networks, while ARP requests are effective on the local subnet. Both avoid TCP state on targets, which matches the analyst's requirement. TCP SYN, TCP FIN, and targeted UDP probes either create TCP state or focus on service discovery rather than pure host liveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ICMP echo requests sent to each address in the subnet range

    Why this is correct

    ICMP echo requests to a range of subnet addresses are a classic host discovery method. Hosts that respond with echo replies are confirmed alive, while non-responders are either offline or blocking ICMP. This technique avoids establishing any TCP connections, which matches the analyst's requirement to identify active hosts without TCP sessions. It is commonly used by tools such as nmap with the ping sweep option.

  • ✗

    TCP SYN packets sent to port 80 on each address in the subnet

    Why it's wrong here

    TCP SYN packets to port 80 attempt to initiate a TCP connection to the target's web service. This is a port scan rather than a pure host discovery technique, and it generates TCP connection attempts that the requirement explicitly excludes. While an open port confirms the host is alive, the SYN traffic itself creates TCP state on the target, violating the no-TCP constraint.

  • ✗

    UDP datagrams sent to port 53 on each address in the subnet

    Why it's wrong here

    UDP datagrams to port 53 target DNS services and are used for service discovery rather than pure host discovery. Although UDP is connectionless, sending to a specific port focuses on identifying a service, not simply confirming host liveness. The requirement is to identify active hosts without TCP connections, and this option targets a specific service, making it less aligned with the stated goal.

  • ✓

    ARP requests broadcast to the subnet for each candidate IP address

    Why this is correct

    ARP requests are broadcast on the local subnet to resolve IP addresses to MAC addresses. A host that replies with its MAC address is confirmed active. ARP scanning avoids TCP entirely and is very effective on a local segment because ARP is rarely filtered. This matches the requirement for host discovery without TCP connections and is a common technique in tools like arp-scan.

  • ✗

    TCP FIN packets sent to port 443 on each address in the subnet

    Why it's wrong here

    TCP FIN packets to port 443 are a stealth port-scanning technique that sends segments with only the FIN flag set. This still uses TCP and targets a specific port, violating the no-TCP requirement. While it can reveal host liveness indirectly through RST responses, it is a port scan rather than a host discovery method and generates TCP traffic on the wire.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.