200-201 Network Intrusion Analysis Practice Question
An analyst is examining a PCAP of what appears to be a covert channel. The analyst observes that the internal host sends ICMP Echo Requests that contain a payload of exactly 48 bytes of non-repeating binary data, and the corresponding Echo Replies always return with a zero-length payload. The payload bytes, when decoded, contain what looks like command strings. Which technique is most consistent with these observations?
⚠ Common exam trap
The trap here is dismissing the traffic as benign ping activity because ICMP is common, when the abnormal payload size and command-like content are the actual red flags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP tunneling using Echo Request payloads as a data exfiltration and command channel
The defining indicators of ICMP tunneling are Echo Request or Echo Reply packets carrying non-standard, often non-repeating or encoded payloads, especially when those payloads contain structured data such as command strings. Normal ping traffic uses predictable, often repeating payloads like alphabetic patterns. The one-way data flow with empty replies here strongly suggests the channel is being used to deliver commands or exfiltrate data covertly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ICMP redirect attack manipulating the host's routing table
Why it's wrong here
ICMP redirect messages are Type 5 and are used by routers to inform a host of a better next hop. The observed traffic consists of Echo Request and Echo Reply (Type 8 and Type 0), not redirects, and the presence of command-like payloads in the requests points to data transfer rather than routing manipulation.
- ✗
ICMP flood denial-of-service attack against the external host
Why it's wrong here
An ICMP flood involves a high volume of Echo Requests with little or no payload aimed at exhausting bandwidth or CPU on the target. Here the payload is a consistent 48 bytes of meaningful binary data, and the traffic appears low-volume and interactive, which is inconsistent with a volumetric flood attack.
- ✗
Smurf attack using the internal host as an unwitting reflector
Why it's wrong here
A Smurf attack spoofs the victim's source address and sends ICMP Echo Requests to a network broadcast address so many hosts reply to the victim. In this capture, the internal host is the actual source of the Echo Requests and receives the replies itself, which rules out a Smurf reflection pattern.
- ✓
ICMP tunneling using Echo Request payloads as a data exfiltration and command channel
Why this is correct
ICMP tunneling abuses the data field of Echo Request and Echo Reply packets to carry arbitrary payloads. The non-repeating binary content and command-like strings in the Echo Request payload, combined with empty Echo Replies, indicate the host is sending data or receiving instructions inside ICMP rather than performing normal reachability checks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.