Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP flood (DDoS)

A DDoS attack using ICMP flood overwhelms the target with echo requests, consuming bandwidth and resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ICMP flood (DDoS)

    Why this is correct

    Many external hosts simultaneously sending small ICMP echo requests to one internal server is a distributed denial-of-service flood. The volume of echo requests exhausts the target's resources, making it unresponsive, which distinguishes it from a single-source ping flood.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing forges link-layer address mappings to redirect local traffic; it generates no flood of ICMP echo requests from external sources. It is the correct finding when a host's ARP cache shows duplicated MAC addresses for the gateway.

  • ✗

    Man-in-the-middle

    Why it's wrong here

    A man-in-the-middle intercepts and relays traffic between two parties, which does not by itself produce a high-volume ICMP echo request flood. It is the diagnosis when traffic is silently relayed or altered, evidenced by certificate or session anomalies.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood sends TCP SYN segments to exhaust connection state, not ICMP echo requests, so the packet type described does not match. SYN floods are the diagnosis when half-open TCP connections saturate a listener's backlog.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.