Courseiva

SSCP Network and Communications Security Practice Question

A security analyst is reviewing network traffic and notices a large number of ICMP echo requests from a single source to multiple destinations within the organization's network. The analyst suspects a reconnaissance attempt. Which type of attack is most likely being performed?

⚠ Common exam trap

Watch out — candidates often confuse a ping sweep, which is for host discovery, with an ICMP flood, which is a denial-of-service attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ping sweep

A ping sweep is a reconnaissance technique that uses ICMP echo requests to identify live hosts on a network. The scenario describes a single source sending ICMP echo requests to multiple destinations, which matches the pattern of a ping sweep. Other ICMP-based attacks like Smurf, Ping of Death, and ICMP flood have different characteristics and objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ping of death

    Why it's wrong here

    The Ping of Death involves sending an ICMP packet larger than the maximum allowed size, causing a buffer overflow on the target. This scenario involves many normal-sized ICMP echo requests to multiple destinations, not a single oversized packet. Therefore, it is not a Ping of Death attack.

  • ✗

    Smurf attack

    Why it's wrong here

    A Smurf attack involves sending ICMP echo requests to a broadcast address with a spoofed source IP, causing many hosts to reply to the victim. In this scenario, the requests are sent to multiple individual destinations, not a broadcast address, and there is no mention of spoofing. Therefore, it is not a Smurf attack.

  • ✓

    Ping sweep

    Why this is correct

    A ping sweep involves sending ICMP echo requests to multiple IP addresses to determine which hosts are active. This is a common reconnaissance technique used to map a network. The scenario describes ICMP echo requests from a single source to multiple destinations, which is characteristic of a ping sweep. Thus, it is the most likely attack.

  • ✗

    ICMP flood

    Why it's wrong here

    An ICMP flood is a denial-of-service attack where a target is overwhelmed with ICMP packets. Here, the traffic is directed to multiple destinations, not a single target, and the volume may not be sufficient to cause a denial of service. The purpose appears to be discovery, not disruption. Thus, it is not an ICMP flood.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.