GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?
⚠ Common exam trap
Candidates often suspect standard diagnostic tools like ping or traceroute, failing to realize that native administrative binaries lack the flexible payload manipulation required for covert data exfiltration without modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
hping3
Hping3 is a popular packet generator and analyzer for TCP/IP that supports crafting arbitrary ICMP packets with custom payload data. Attackers frequently leverage hping3 or similar custom scripting tools to exfiltrate data through covert channels when standard protocols are blocked by perimeter firewalls, making process history analysis critical for detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ping
Why it's wrong here
The standard system ping utility is designed primarily for basic connectivity troubleshooting and network diagnostics. While it sends ICMP echo requests, native implementations do not easily permit inserting arbitrary multi-byte application payloads into outgoing packets without source code modification.
- ✗
traceroute
Why it's wrong here
Traceroute maps the network path by manipulating the Time to Live (TTL) field in IP packets and typically relies on UDP or ICMP datagrams with specific port numbers. It lacks features for encoding arbitrary payload streams for covert data exfiltration over ICMP.
- ✓
hping3
Why this is correct
Hping3 enables system administrators and security testers to assemble and send custom ICMP, TCP, and UDP packets. Threat actors leverage its advanced packet crafting capabilities to smuggle encoded internal data through restricted network perimeters via covert channels.
- ✗
tcpdump
Why it's wrong here
Tcpdump is a powerful command-line packet analyzer used strictly for capturing and inspecting network traffic passing through an interface. It functions as a passive observer and monitoring tool rather than an active packet generator capable of creating outbound covert channels.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.