ISC2 CC Network Security Practice Question
A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP flood (DDoS)
A DDoS attack using ICMP flood overwhelms the target with echo requests, consuming bandwidth and resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ICMP flood (DDoS)
Why this is correct
Many external hosts simultaneously sending small ICMP echo requests to one internal server is a distributed denial-of-service flood. The volume of echo requests exhausts the target's resources, making it unresponsive, which distinguishes it from a single-source ping flood.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing forges link-layer address mappings to redirect local traffic; it generates no flood of ICMP echo requests from external sources. It is the correct finding when a host's ARP cache shows duplicated MAC addresses for the gateway.
- ✗
Man-in-the-middle
Why it's wrong here
A man-in-the-middle intercepts and relays traffic between two parties, which does not by itself produce a high-volume ICMP echo request flood. It is the diagnosis when traffic is silently relayed or altered, evidenced by certificate or session anomalies.
- ✗
SYN flood
Why it's wrong here
A SYN flood sends TCP SYN segments to exhaust connection state, not ICMP echo requests, so the packet type described does not match. SYN floods are the diagnosis when half-open TCP connections saturate a listener's backlog.
Go deeper
Related to this question
Key term
DDoS
A DDoS (Distributed Denial-of-Service) attack is a malicious attempt to disrupt normal traffic of a targeted server, service, or network by overwhelming it with a flood of internet traffic from multiple compromised systems.
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.