Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

An analyst is investigating an alert for a potential ICMP tunneling attack. The analyst reviews a PCAP and notices a series of ICMP Echo Request packets with unusually large payloads (over 1000 bytes) and varying payload contents, sent from an internal host to an external IP address. The external host replies with ICMP Echo Reply packets of similar size. Which characteristic most strongly supports the conclusion that this is ICMP tunneling rather than normal ping traffic?

⚠ Common exam trap

The trap here is focusing on the ICMP type or timing as the malicious indicator, when the real signal is the payload size and content variation that reveals data encapsulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The payload size is consistently large and the contents are non-repetitive, indicating that data is being encapsulated in the ICMP payload.

The strongest indicator of ICMP tunneling is the presence of large, non-repetitive payloads in Echo Requests and Replies, which suggests data encapsulation. Normal ping uses small, often patterned payloads. The other options describe normal ICMP characteristics, such as standard types, regular timing, or IP header fields, none of which specifically indicate tunneling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The payload size is consistently large and the contents are non-repetitive, indicating that data is being encapsulated in the ICMP payload.

    Why this is correct

    Normal ping payloads are typically small (e.g., 32 or 64 bytes) and often consist of a repeating pattern or timestamp. Large, varying payloads suggest that actual data is being carried inside the ICMP packets, which is the essence of ICMP tunneling. The consistent size and non-repetitive content further indicate a structured data transfer, supporting the conclusion of tunneling.

  • ✗

    The ICMP packets use Type 8 and Type 0 codes, which are reserved for diagnostic purposes and should not carry data.

    Why it's wrong here

    Type 8 (Echo Request) and Type 0 (Echo Reply) are standard for ping and are not reserved exclusively for diagnostics without data. They are commonly used for connectivity testing. While they can carry data, the type itself does not indicate tunneling. This option misstates the purpose of these ICMP types and would not differentiate tunneling from normal ping.

  • ✗

    The ICMP Echo Requests are sent at regular intervals, which is a known signature of ICMP tunneling tools.

    Why it's wrong here

    Regular intervals are more characteristic of beaconing or keep-alive traffic, not necessarily ICMP tunneling. Normal ping can also be sent at regular intervals (e.g., ping -i). The regularity alone does not distinguish tunneling from automated monitoring. The key indicator is the payload content and size, not the timing.

  • ✗

    The external host responds with Echo Replies that have a different IP identification field than the requests, which indicates packet fragmentation.

    Why it's wrong here

    The IP identification field is used for reassembly and can vary between packets; it does not indicate tunneling. Fragmentation is a separate condition indicated by the MF flag or fragment offset. This option confuses normal IP header behavior with tunneling indicators and would not support the conclusion.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.