Courseiva

SSCP Network and Communications Security Practice Question

Which TWO of the following are characteristics of a Smurf attack? (Select TWO)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Uses ICMP echo requests

Smurf attacks send ICMP echo requests to a broadcast address with a spoofed source IP, causing all hosts to reply to the victim, leading to amplification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Requires fragmented packets

    Why it's wrong here

    Smurf attacks rely on ICMP echo requests sent to a broadcast address, which are not fragmented; fragmentation is characteristic of teardrop and ping-of-death attacks. It is tempting because both abuse ICMP, and would be correct if the question asked about malformed overlapping fragments crashing a target.

  • ✓

    Uses ICMP echo requests

    Why this is correct

    The attacker sends ICMP echo requests with a spoofed source address to a network's broadcast address, so every host replies to the victim. This ICMP echo mechanism is the defining traffic characteristic of a Smurf attack.

  • ✗

    Exploits TCP SYN handshake

    Why it's wrong here

    A Smurf attack floods a victim with ICMP echo replies from spoofed broadcast addresses; it never completes or abuses a TCP three-way handshake. It is tempting because SYN floods also use spoofed source addresses, and would be correct if the question described exhausting a server's half-open connection table.

  • ✗

    Targets DNS resolvers

    Why it's wrong here

    Smurf attacks abuse ICMP directed broadcasts to an amplifier network, not DNS resolvers; DNS reflection is a separate amplification technique. It is tempting because both spoof the victim's address to redirect amplified replies, and would be correct if the stem described overwhelming a target via DNS response traffic.

  • ✓

    Amplifies traffic by using broadcast addresses

    Why this is correct

    Directing ICMP echo requests to a broadcast address makes every host on the subnet respond to the spoofed victim, multiplying traffic far beyond what the attacker sends. This amplification via broadcast addresses is the Smurf attack's core mechanism.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which attack sends a flood of forged ICMP echo requests to a network's broadcast address to overwhelm a target?

easy
  • A.Ping of death
  • ✓ B.Smurf attack
  • C.SYN flood
  • D.DNS amplification

Why B: A Smurf attack sends a flood of forged ICMP echo requests to a network's broadcast address with the source IP spoofed as the target's IP. All hosts on the network respond to the broadcast, overwhelming the target with ICMP echo replies. This is a classic amplification attack. Therefore, Smurf attack is correct.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.