200-201 Network Intrusion Analysis Practice Question
An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?
⚠ Common exam trap
The trap here is treating all ICMP traffic as benign troubleshooting traffic and not inspecting the payload size and content of echo request and reply packets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP tunneling for data exfiltration
Oversized ICMP echo packets carrying encoded, non-standard payloads in both directions strongly indicate ICMP tunneling, a common method for covert data transfer and exfiltration. Because many networks permit ping for troubleshooting, attackers abuse it to move data past controls that do not inspect ICMP payloads. The other options describe different ICMP-based behaviors that do not involve encoded data in echo payloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smurf attack amplification
Why it's wrong here
A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source, generating many replies to the victim. The scenario describes a single internal host exchanging echo traffic with one external host and carrying encoded fragments, which does not match the amplification pattern. Smurf attacks also do not rely on large encoded payloads in the echo data.
- ✗
Path MTU discovery using oversized ICMP
Why it's wrong here
Path MTU discovery uses ICMP destination unreachable with the fragmentation-needed code, not echo request and reply with encoded payloads. The payloads here are non-standard and asymmetric, which is inconsistent with MTU discovery messages. MTU discovery packets are small control messages and do not carry file fragments in echo data.
- ✗
ICMP redirect manipulation
Why it's wrong here
ICMP redirect messages are type 5 and are used to inform a host of a better route; they do not carry large encoded payloads in echo request or reply packets. The observed traffic is echo request and echo reply, not redirect. Redirect manipulation changes routing behavior and would not involve transferring file fragments inside echo data.
- ✓
ICMP tunneling for data exfiltration
Why this is correct
ICMP tunneling embeds data inside echo request and reply payloads, which is exactly what the oversized, encoded, non-standard payloads indicate. The asymmetry in payload size and the presence of encoded fragments suggest a tool using ICMP as a transport to move data out of the network. This technique bypasses controls that allow ping but do not inspect ICMP payload content.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.