Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst examines a PCAP and finds a series of UDP packets sent to multiple ports on a target. The target responds with ICMP 'Destination Unreachable (Port Unreachable)' messages for each port. What type of scan is being performed?

⚠ Common exam trap

The trap is assuming any scan that elicits ICMP responses is a TCP-based stealth scan; candidates must remember that ICMP Port Unreachable is specifically the closed-port response for UDP, not TCP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

UDP scan

A UDP scan works by sending a UDP packet to a target port. If the port is closed, the target responds with an ICMP Port Unreachable message (Type 3, Code 3). If the port is open, the service may or may not reply, so the absence of an ICMP unreachable is interpreted as 'open|filtered.' The pattern of UDP probes followed by ICMP Port Unreachable responses is the signature of a UDP scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    UDP scan

    Why this is correct

    Sending UDP datagrams to successive ports and receiving ICMP Port Unreachable replies for closed ones is the signature of a UDP scan, which maps open UDP services by their silence versus closed ports returning ICMP unreachable messages.

  • ✗

    SYN scan

    Why it's wrong here

    A SYN scan sends TCP SYN packets and interprets SYN-ACK or RST replies, so it cannot produce ICMP port-unreachable messages from UDP probes. It is tempting because SYN scanning also maps open ports, but it operates at the TCP layer and would be correct when probing TCP services rather than UDP.

  • ✗

    Xmas scan

    Why it's wrong here

    An Xmas scan sends TCP segments with FIN, PSH and URG flags set, expecting RST from closed ports, so it never elicits ICMP port-unreachable replies. It is tempting as another port-scanning technique, but it is the right choice when identifying TCP ports via malformed flag combinations, not UDP.

  • ✗

    FIN scan

    Why it's wrong here

    A FIN scan sends a bare TCP FIN segment and treats RST responses as closed ports, so it cannot generate ICMP port-unreachable messages. It is tempting because it is also a stealthy port scan, but it is correct when probing TCP ports on systems that silently drop FIN packets.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.