SSCP Network and Communications Security Practice Question
Which TWO of the following are characteristics of a Smurf attack? (Select TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Uses ICMP echo requests
Smurf attacks send ICMP echo requests to a broadcast address with a spoofed source IP, causing all hosts to reply to the victim, leading to amplification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Requires fragmented packets
Why it's wrong here
Smurf attacks rely on ICMP echo requests sent to a broadcast address, which are not fragmented; fragmentation is characteristic of teardrop and ping-of-death attacks. It is tempting because both abuse ICMP, and would be correct if the question asked about malformed overlapping fragments crashing a target.
- ✓
Uses ICMP echo requests
Why this is correct
The attacker sends ICMP echo requests with a spoofed source address to a network's broadcast address, so every host replies to the victim. This ICMP echo mechanism is the defining traffic characteristic of a Smurf attack.
- ✗
Exploits TCP SYN handshake
Why it's wrong here
A Smurf attack floods a victim with ICMP echo replies from spoofed broadcast addresses; it never completes or abuses a TCP three-way handshake. It is tempting because SYN floods also use spoofed source addresses, and would be correct if the question described exhausting a server's half-open connection table.
- ✗
Targets DNS resolvers
Why it's wrong here
Smurf attacks abuse ICMP directed broadcasts to an amplifier network, not DNS resolvers; DNS reflection is a separate amplification technique. It is tempting because both spoof the victim's address to redirect amplified replies, and would be correct if the stem described overwhelming a target via DNS response traffic.
- ✓
Amplifies traffic by using broadcast addresses
Why this is correct
Directing ICMP echo requests to a broadcast address makes every host on the subnet respond to the spoofed victim, multiplying traffic far beyond what the attacker sends. This amplification via broadcast addresses is the Smurf attack's core mechanism.
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which attack sends a flood of forged ICMP echo requests to a network's broadcast address to overwhelm a target?
easy- A.Ping of death
- ✓ B.Smurf attack
- C.SYN flood
- D.DNS amplification
Why B: A Smurf attack sends a flood of forged ICMP echo requests to a network's broadcast address with the source IP spoofed as the target's IP. All hosts on the network respond to the broadcast, overwhelming the target with ICMP echo replies. This is a classic amplification attack. Therefore, Smurf attack is correct.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.