Courseiva

GCIH Practice Question: Detecting Exploitation and Covert Communication Tools

During incident response, you observe that a compromised host is sending ICMP echo request packets with a payload size of 1000 bytes to an external IP. The payload appears to contain non-printable characters. What is the most likely explanation?

⚠ Common exam trap

The trap here is assuming that any large ICMP packet is a ping flood, when the payload content and destination specificity indicate tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The host is using ICMP tunneling for covert communication.

The correct answer is ICMP tunneling for covert communication. Large ICMP packets with non-printable payloads sent to a single external IP are a classic sign of ICMP tunneling, where data is hidden in the payload to evade detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The host is experiencing a network loop.

    Why it's wrong here

    Network loops typically cause broadcast storms and high CPU usage, but they do not generate ICMP packets with large, non-printable payloads directed to a single external IP. The specificity of the traffic points to intentional communication, not a loop.

  • ✗

    The host is infected with a worm that scans for vulnerabilities.

    Why it's wrong here

    Worms often scan by sending TCP SYN packets or ICMP echo requests to multiple hosts, but they typically use small payloads and target many IPs. Here, the large payload to a single external IP suggests data transfer, not scanning.

  • ✗

    The host is performing a ping flood attack.

    Why it's wrong here

    A ping flood typically involves a high volume of ICMP echo requests with standard or large payloads, but the payload is usually empty or filled with a repeating pattern. The non-printable characters and specific size suggest data transfer, not a denial-of-service flood.

  • ✓

    The host is using ICMP tunneling for covert communication.

    Why this is correct

    ICMP tunneling hides data within ICMP echo request and reply packets. The large, non-printable payload is a strong indicator that the attacker is using ICMP as a covert channel to send commands or exfiltrate data, often to bypass firewalls that allow ICMP.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.