Courseiva
Networking and Protocols →hardMultiple Select

GSEC Networking and Protocols Practice Question

A security engineer is analyzing why a remote user's VPN session intermittently fails to reach internal resources even though the tunnel itself stays up. Packet captures show large packets are dropped while small ones succeed, and the engineer suspects a path MTU discovery problem. Which TWO conditions would cause this behavior on the path between the client and the internal server? (Choose two.)

⚠ Common exam trap

The trap here is blaming performance-tuning settings like window size or cipher strength for a symptom that is fundamentally about packet size and ICMP signaling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An intermediate firewall blocks all ICMP Destination Unreachable messages, including the fragmentation-needed type.

Path MTU discovery relies on ICMP fragmentation-needed messages to signal senders to shrink packets. Filtering those ICMP messages, or setting the Don't Fragment bit on encapsulated packets larger than the real path MTU, leaves the sender unaware and causes silent drops of large packets while small ones pass. Both conditions match the observed size-dependent failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The internal server uses a smaller TCP receive window than the client advertises during the handshake.

    Why it's wrong here

    The TCP receive window governs flow control, not path MTU. A smaller window limits how much unacknowledged data can be in flight, which can reduce throughput but does not cause large packets to be dropped while small ones succeed. Window size negotiation is a performance tuning matter and cannot explain the fragmentation-related drop pattern observed in the capture.

  • ✗

    The client's DNS resolver returns a stale record pointing to a decommissioned server address.

    Why it's wrong here

    A stale DNS record would cause connection failures to a specific host regardless of packet size, not a pattern where small packets pass and large ones drop. The capture shows the tunnel is up and some traffic succeeds, so name resolution is functioning. DNS caching issues do not produce fragmentation-related, size-dependent drops on an established path.

  • ✗

    The client and server negotiated a weak cipher suite during the VPN handshake.

    Why it's wrong here

    Cipher suite strength affects confidentiality and integrity, not packet size handling. A weak cipher would not selectively drop large packets, and modern suites have negligible effect on MTU. The symptom of small packets succeeding while large packets fail is a size-dependent forwarding problem, so cryptographic negotiation parameters are irrelevant to the described fault.

  • ✓

    An intermediate firewall blocks all ICMP Destination Unreachable messages, including the fragmentation-needed type.

    Why this is correct

    Path MTU discovery depends on ICMP Destination Unreachable with the fragmentation-needed code to tell the sender to reduce packet size. If that ICMP is filtered, the sender never learns the smaller MTU and keeps emitting oversized packets that are silently dropped. This exactly produces the pattern where small packets pass and large ones fail, making it a genuine cause in this scenario.

  • ✓

    The VPN concentrator sets the Don't Fragment bit on encapsulated packets but the underlying path supports a smaller MTU than the tunnel interface.

    Why this is correct

    When the outer packet carries the Don't Fragment bit and exceeds the path MTU, routers cannot fragment it and must drop it, returning fragmentation-needed. If the tunnel interface MTU is larger than the real path MTU, oversized encapsulated packets vanish. This mismatch between tunnel MTU and path MTU is a classic cause of large-packet failure inside a working VPN tunnel.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.