Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst reviews a PCAP and sees a host receive an unsolicited ICMP echo reply containing an embedded payload, followed by the host initiating a TCP connection to an internal server on port 445. The ICMP payload begins with bytes that decode to a URL path. Which analysis conclusion is most defensible?

⚠ Common exam trap

The trap here is treating ICMP as inherently harmless monitoring traffic; unsolicited replies with embedded data are not normal health checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ICMP payload is likely a covert channel delivering a command that triggered the SMB connection

An unsolicited ICMP echo reply carrying a decodable URL path is a hallmark of ICMP-based covert command delivery. Pairing it with a subsequent outbound SMB connection to an internal server suggests the delivered instruction told the host to reach a share for lateral movement or tool retrieval. The direction of the TCP handshake confirms the host is the client, and the payload is coherent, not a fragmentation artifact, so the covert-channel conclusion is the most defensible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ICMP payload is a fragmentation artifact and should be ignored

    Why it's wrong here

    Fragmentation artifacts appear as partial headers or overlapping fragments, not as a coherent decodable URL path. The payload here decodes to a meaningful string, which indicates intentional data embedding rather than random fragmentation noise. Treating it as an artifact would discard a strong indicator of a covert channel and break the correlation with the SMB connection.

  • ✗

    The ICMP traffic is a benign network health check and the SMB connection is unrelated

    Why it's wrong here

    Benign ICMP echo replies are solicited by a prior echo request and carry no embedded URL-like data. Here the reply is unsolicited and contains a decodable URL path, which is not normal for health checks. The subsequent SMB connection on port 445 to an internal server also fits a post-exploitation lateral movement pattern, so dismissing the two events as unrelated ignores a plausible cause-and-effect chain.

  • ✓

    The ICMP payload is likely a covert channel delivering a command that triggered the SMB connection

    Why this is correct

    Unsolicited ICMP echo replies with embedded URL-like data are a known covert channel for command delivery. The immediate SMB connection to an internal server on port 445 is consistent with the delivered command instructing the host to move laterally or access a share. Correlating the payload content with the follow-on SMB session gives a defensible intrusion narrative, so this conclusion matches the evidence best.

  • ✗

    The SMB connection indicates the host is acting as a file server for the attacker

    Why it's wrong here

    The host initiates the TCP connection to port 445, making it the client, not the server. A compromised host serving files to an attacker would typically listen on 445 and accept inbound connections. Misreading the direction of the TCP handshake leads to the wrong role assignment, and the ICMP payload delivery would remain unexplained under this interpretation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.