Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?

⚠ Common exam trap

The trap here is treating all ICMP traffic as benign troubleshooting traffic and not inspecting the payload size and content of echo request and reply packets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP tunneling for data exfiltration

Oversized ICMP echo packets carrying encoded, non-standard payloads in both directions strongly indicate ICMP tunneling, a common method for covert data transfer and exfiltration. Because many networks permit ping for troubleshooting, attackers abuse it to move data past controls that do not inspect ICMP payloads. The other options describe different ICMP-based behaviors that do not involve encoded data in echo payloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Smurf attack amplification

    Why it's wrong here

    A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source, generating many replies to the victim. The scenario describes a single internal host exchanging echo traffic with one external host and carrying encoded fragments, which does not match the amplification pattern. Smurf attacks also do not rely on large encoded payloads in the echo data.

  • ✗

    Path MTU discovery using oversized ICMP

    Why it's wrong here

    Path MTU discovery uses ICMP destination unreachable with the fragmentation-needed code, not echo request and reply with encoded payloads. The payloads here are non-standard and asymmetric, which is inconsistent with MTU discovery messages. MTU discovery packets are small control messages and do not carry file fragments in echo data.

  • ✗

    ICMP redirect manipulation

    Why it's wrong here

    ICMP redirect messages are type 5 and are used to inform a host of a better route; they do not carry large encoded payloads in echo request or reply packets. The observed traffic is echo request and echo reply, not redirect. Redirect manipulation changes routing behavior and would not involve transferring file fragments inside echo data.

  • ✓

    ICMP tunneling for data exfiltration

    Why this is correct

    ICMP tunneling embeds data inside echo request and reply payloads, which is exactly what the oversized, encoded, non-standard payloads indicate. The asymmetry in payload size and the presence of encoded fragments suggest a tool using ICMP as a transport to move data out of the network. This technique bypasses controls that allow ping but do not inspect ICMP payload content.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.