200-201 Network Intrusion Analysis Practice Question
An analyst reviews a PCAP and sees a host receive an unsolicited ICMP echo reply containing an embedded payload, followed by the host initiating a TCP connection to an internal server on port 445. The ICMP payload begins with bytes that decode to a URL path. Which analysis conclusion is most defensible?
⚠ Common exam trap
The trap here is treating ICMP as inherently harmless monitoring traffic; unsolicited replies with embedded data are not normal health checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ICMP payload is likely a covert channel delivering a command that triggered the SMB connection
An unsolicited ICMP echo reply carrying a decodable URL path is a hallmark of ICMP-based covert command delivery. Pairing it with a subsequent outbound SMB connection to an internal server suggests the delivered instruction told the host to reach a share for lateral movement or tool retrieval. The direction of the TCP handshake confirms the host is the client, and the payload is coherent, not a fragmentation artifact, so the covert-channel conclusion is the most defensible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ICMP payload is a fragmentation artifact and should be ignored
Why it's wrong here
Fragmentation artifacts appear as partial headers or overlapping fragments, not as a coherent decodable URL path. The payload here decodes to a meaningful string, which indicates intentional data embedding rather than random fragmentation noise. Treating it as an artifact would discard a strong indicator of a covert channel and break the correlation with the SMB connection.
- ✗
The ICMP traffic is a benign network health check and the SMB connection is unrelated
Why it's wrong here
Benign ICMP echo replies are solicited by a prior echo request and carry no embedded URL-like data. Here the reply is unsolicited and contains a decodable URL path, which is not normal for health checks. The subsequent SMB connection on port 445 to an internal server also fits a post-exploitation lateral movement pattern, so dismissing the two events as unrelated ignores a plausible cause-and-effect chain.
- ✓
The ICMP payload is likely a covert channel delivering a command that triggered the SMB connection
Why this is correct
Unsolicited ICMP echo replies with embedded URL-like data are a known covert channel for command delivery. The immediate SMB connection to an internal server on port 445 is consistent with the delivered command instructing the host to move laterally or access a share. Correlating the payload content with the follow-on SMB session gives a defensible intrusion narrative, so this conclusion matches the evidence best.
- ✗
The SMB connection indicates the host is acting as a file server for the attacker
Why it's wrong here
The host initiates the TCP connection to port 445, making it the client, not the server. A compromised host serving files to an attacker would typically listen on 445 and accept inbound connections. Misreading the direction of the TCP handshake leads to the wrong role assignment, and the ICMP payload delivery would remain unexplained under this interpretation.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.