Courseiva

GCIH Practice Question: Detecting Exploitation and Covert Communication Tools

During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?

⚠ Common exam trap

Candidates often suspect standard diagnostic tools like ping or traceroute, failing to realize that native administrative binaries lack the flexible payload manipulation required for covert data exfiltration without modification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hping3

Hping3 is a popular packet generator and analyzer for TCP/IP that supports crafting arbitrary ICMP packets with custom payload data. Attackers frequently leverage hping3 or similar custom scripting tools to exfiltrate data through covert channels when standard protocols are blocked by perimeter firewalls, making process history analysis critical for detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ping

    Why it's wrong here

    The standard system ping utility is designed primarily for basic connectivity troubleshooting and network diagnostics. While it sends ICMP echo requests, native implementations do not easily permit inserting arbitrary multi-byte application payloads into outgoing packets without source code modification.

  • ✗

    traceroute

    Why it's wrong here

    Traceroute maps the network path by manipulating the Time to Live (TTL) field in IP packets and typically relies on UDP or ICMP datagrams with specific port numbers. It lacks features for encoding arbitrary payload streams for covert data exfiltration over ICMP.

  • ✓

    hping3

    Why this is correct

    Hping3 enables system administrators and security testers to assemble and send custom ICMP, TCP, and UDP packets. Threat actors leverage its advanced packet crafting capabilities to smuggle encoded internal data through restricted network perimeters via covert channels.

  • ✗

    tcpdump

    Why it's wrong here

    Tcpdump is a powerful command-line packet analyzer used strictly for capturing and inspecting network traffic passing through an interface. It functions as a passive observer and monitoring tool rather than an active packet generator capable of creating outbound covert channels.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.