200-201 Network Intrusion Analysis Practice Question
An analyst examines a PCAP and finds a series of UDP packets sent to multiple ports on a target. The target responds with ICMP 'Destination Unreachable (Port Unreachable)' messages for each port. What type of scan is being performed?
⚠ Common exam trap
The trap is assuming any scan that elicits ICMP responses is a TCP-based stealth scan; candidates must remember that ICMP Port Unreachable is specifically the closed-port response for UDP, not TCP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UDP scan
A UDP scan works by sending a UDP packet to a target port. If the port is closed, the target responds with an ICMP Port Unreachable message (Type 3, Code 3). If the port is open, the service may or may not reply, so the absence of an ICMP unreachable is interpreted as 'open|filtered.' The pattern of UDP probes followed by ICMP Port Unreachable responses is the signature of a UDP scan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
UDP scan
Why this is correct
Sending UDP datagrams to successive ports and receiving ICMP Port Unreachable replies for closed ones is the signature of a UDP scan, which maps open UDP services by their silence versus closed ports returning ICMP unreachable messages.
- ✗
SYN scan
Why it's wrong here
A SYN scan sends TCP SYN packets and interprets SYN-ACK or RST replies, so it cannot produce ICMP port-unreachable messages from UDP probes. It is tempting because SYN scanning also maps open ports, but it operates at the TCP layer and would be correct when probing TCP services rather than UDP.
- ✗
Xmas scan
Why it's wrong here
An Xmas scan sends TCP segments with FIN, PSH and URG flags set, expecting RST from closed ports, so it never elicits ICMP port-unreachable replies. It is tempting as another port-scanning technique, but it is the right choice when identifying TCP ports via malformed flag combinations, not UDP.
- ✗
FIN scan
Why it's wrong here
A FIN scan sends a bare TCP FIN segment and treats RST responses as closed ports, so it cannot generate ICMP port-unreachable messages. It is tempting because it is also a stealthy port scan, but it is correct when probing TCP ports on systems that silently drop FIN packets.
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.