GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
During an incident response engagement on a Linux server, you discover an attacker has established covert command and control using a custom backdoor communicating over raw ICMP sockets. Which network analysis method provides the most reliable detection mechanism for this specific covert channel regardless of packet payload obfuscation?
⚠ Common exam trap
Candidates often assume that deep packet inspection or payload signatures are required to detect ICMP covert channels, completely overlooking statistical traffic profiling and timing anomaly detection methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyzing ICMP packet frequency, inter-arrival timing anomalies, and payload size distributions across network flows.
Monitoring packet frequency and timing anomalies identifies ICMP tunneling because legitimate diagnostic tools like ping operate at steady, predictable intervals. Attackers forcing high-volume data transmissions create irregular burst patterns and anomalous payload sizes that standard baseline monitoring quickly highlights as suspicious behavior. Effective incident handlers must look beyond simple signature detection when analyzing sophisticated tunneling techniques. Understanding foundational network protocols allows analysts to spot statistical deviations even when cryptographic encryption completely obscures the underlying application layer payload contents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scanning all active network interfaces for unauthorized listening TCP ports bound to high-numbered ports.
Why it's wrong here
Raw ICMP sockets do not rely on standard TCP transport layer listener ports, rendering traditional port scanning methods completely ineffective for identifying this specific type of covert communication mechanism operating directly over Layer 3 network protocols.
- ✓
Analyzing ICMP packet frequency, inter-arrival timing anomalies, and payload size distributions across network flows.
Why this is correct
Raw ICMP tunnelling hides commands inside payloads, so signature or content inspection fails once obfuscated. Statistical analysis of packet frequency, inter-arrival timing and payload size distributions exposes the anomalous traffic pattern inherent to the covert channel, regardless of payload encoding.
- ✗
Reviewing traditional stateful firewall drop logs for blocked SYN packets originating from internal server zones.
Why it's wrong here
Stateful firewall drop logs record blocked SYN packets, whereas the ICMP backdoor's traffic is permitted outbound and produces no SYN drops. It is tempting because firewall logs reveal scanning and blocked inbound connections, but covert channels require payload or protocol-anomaly inspection, not connection-refusal records.
- ✗
Inspecting standard application layer web server access logs for anomalous HTTP POST request parameter values.
Why it's wrong here
HTTP POST parameters sit at the application layer, so a raw ICMP backdoor never generates them; inspection would find nothing. It is tempting because web-log analysis detects many C2 channels, but it is correct only when the implant tunnels over HTTP rather than raw ICMP sockets.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.