200-201 Network Intrusion Analysis Practice Question
A SOC analyst notices an internal host transmitting a series of ICMP Echo Request packets to an external IP, each with a payload size of exactly 1024 bytes and a repeating pattern. The echo replies are consistently the same size. Which type of activity does this most likely indicate?
⚠ Common exam trap
The trap here is assuming that any ICMP traffic is benign network troubleshooting, ignoring the unusual payload size and pattern that point to tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP tunneling
The correct answer is ICMP tunneling because the traffic shows large, fixed-size ICMP payloads with repeating patterns and matching replies, which are hallmarks of data being hidden inside ICMP Echo packets. Normal ICMP usage involves small, variable payloads for diagnostics, not consistent large payloads, indicating a covert channel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Legitimate network latency testing
Why it's wrong here
Latency testing (e.g., ping) uses small, standard-sized ICMP packets, often 32-64 bytes, and does not embed repeating patterns. The large, fixed-size payloads and consistent replies suggest intentional data transfer, not simple latency measurement, making this unlikely for legitimate testing.
- ✓
ICMP tunneling
Why this is correct
Large, fixed-size ICMP payloads with repeating patterns and matching replies indicate data being encapsulated inside ICMP Echo packets. Normal ping payloads are small (often 32-64 bytes) and random. The consistent size and pattern suggest a covert channel using ICMP tunneling tools like ptunnel or icmpsh to exfiltrate or communicate stealthily.
- ✗
Network reconnaissance via ping sweep
Why it's wrong here
A ping sweep sends small ICMP Echo Requests to multiple IP addresses to discover live hosts. Here, the traffic is directed to a single external IP with large, repetitive payloads, which is not characteristic of a sweep. Reconnaissance would involve varied destination addresses and minimal payload.
- ✗
ICMP flood denial-of-service
Why it's wrong here
An ICMP flood typically involves a high volume of Echo Requests from many sources to overwhelm a target, not a single host sending consistent, large payloads to one external IP. The described traffic is low-volume and patterned, which is inconsistent with a flood, and the replies are normal, not indicative of DoS.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.