SSCP Network and Communications Security Practice Question
A security analyst is reviewing network traffic and notices a large number of ICMP echo requests from a single source to multiple destinations within the organization's network. The analyst suspects a reconnaissance attempt. Which type of attack is most likely being performed?
⚠ Common exam trap
Watch out — candidates often confuse a ping sweep, which is for host discovery, with an ICMP flood, which is a denial-of-service attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ping sweep
A ping sweep is a reconnaissance technique that uses ICMP echo requests to identify live hosts on a network. The scenario describes a single source sending ICMP echo requests to multiple destinations, which matches the pattern of a ping sweep. Other ICMP-based attacks like Smurf, Ping of Death, and ICMP flood have different characteristics and objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ping of death
Why it's wrong here
The Ping of Death involves sending an ICMP packet larger than the maximum allowed size, causing a buffer overflow on the target. This scenario involves many normal-sized ICMP echo requests to multiple destinations, not a single oversized packet. Therefore, it is not a Ping of Death attack.
- ✗
Smurf attack
Why it's wrong here
A Smurf attack involves sending ICMP echo requests to a broadcast address with a spoofed source IP, causing many hosts to reply to the victim. In this scenario, the requests are sent to multiple individual destinations, not a broadcast address, and there is no mention of spoofing. Therefore, it is not a Smurf attack.
- ✓
Ping sweep
Why this is correct
A ping sweep involves sending ICMP echo requests to multiple IP addresses to determine which hosts are active. This is a common reconnaissance technique used to map a network. The scenario describes ICMP echo requests from a single source to multiple destinations, which is characteristic of a ping sweep. Thus, it is the most likely attack.
- ✗
ICMP flood
Why it's wrong here
An ICMP flood is a denial-of-service attack where a target is overwhelmed with ICMP packets. Here, the traffic is directed to multiple destinations, not a single target, and the volume may not be sufficient to cause a denial of service. The purpose appears to be discovery, not disruption. Thus, it is not an ICMP flood.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.