CISSP Communication and Network Security Practice Question
An incident responder is analyzing a network compromise that involved ICMP attacks. Which THREE types of ICMP attacks could have been used to disrupt network operations? (Select three.)
⚠ Common exam trap
A common mix-up: candidates confuse ARP poisoning and SYN flood with ICMP attacks because they are common network attacks, but they operate at different layers (Layer 2 and Layer 4, respectively) and do not use ICMP as the attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smurf attack
The Smurf attack (A) is correct because it spoofs the victim's source IP and sends ICMP echo requests to a network's broadcast address, causing every host to reply to the victim and amplifying traffic to disrupt operations. The ICMP redirect attack (B) is correct because forged ICMP Type 5 redirect messages can alter a host's routing table, sending traffic through an attacker-controlled path and disrupting or intercepting network communications. The Ping of Death (E) is correct because it sends malformed or oversized ICMP echo request packets (historically exceeding the 65,535-byte IP packet limit) that can crash or destabilize vulnerable systems. ARP poisoning (C) is not an ICMP attack; it manipulates ARP cache entries at Layer 2. SYN flood (D) is a TCP-based attack abusing the three-way handshake, not ICMP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Smurf attack
Why this is correct
A Smurf attack is a distributed denial-of-service (DDoS) technique that leverages ICMP echo requests and IP broadcast addresses. An attacker sends a large number of ICMP echo requests to a network's broadcast address, spoofing the source IP to be the victim's address. All hosts on that network then reply to the spoofed source, flooding the victim with an overwhelming volume of ICMP echo replies, effectively causing a denial of service.
- ✓
ICMP redirect attack
Why this is correct
An ICMP redirect attack involves an adversary sending forged ICMP Type 5 Redirect messages to a target host. These malicious messages instruct the host to send its traffic for a specific destination through a different, attacker-controlled gateway, rather than the legitimate one. This manipulation of the host's routing table allows the attacker to intercept, inspect, or modify network traffic, establishing a Man-in-the-Middle position without directly compromising the router itself.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning is a Layer 2 attack that manipulates the Address Resolution Protocol (ARP) cache on a local network. An attacker sends spoofed ARP messages to associate their own MAC address with the IP address of another host, such as the default gateway or another victim. This redirects traffic intended for the legitimate host through the attacker's machine, making it fundamentally distinct from ICMP-based attacks which operate at Layer 3.
- ✗
SYN flood
Why it's wrong here
A SYN flood is a denial-of-service attack that exploits the TCP three-way handshake mechanism at Layer 4. The attacker sends a rapid succession of TCP SYN requests to a target server but never completes the handshake by sending the final ACK. This leaves the server with numerous half-open connections, exhausting its connection table and preventing legitimate clients from establishing new connections, making it entirely unrelated to ICMP.
- ✓
Ping of Death
Why this is correct
The Ping of Death attack exploits vulnerabilities in how systems handle oversized ICMP packets. An attacker sends an ICMP echo request packet that, when fragmented and reassembled, exceeds the maximum allowable IP packet size of 65,535 bytes. This malformed, oversized packet can cause buffer overflows, system crashes, or reboots on vulnerable operating systems and network devices due to improper memory allocation or error handling.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.