CompTIA CySA+ (CS0-003)Security OperationsHard
An analyst captures traffic and observes the following pattern from an internal workstation to an external host over a 45-minute window: `10.1.5.22 -> 198.51.100.9 ICMP echo request, seq=1..900, len=1400 bytes, interval ~3s` `198.51.100.9 -> 10.1.5.22 ICMP echo reply, payload contains variable non-standard ASCII data` No legitimate network monitoring tool is configured to ping this host. Which of the following BEST explains this traffic pattern?
- AICMP tunneling used for covert data exfiltration or C2
- BA standard network availability monitoring probe
- CARP cache poisoning between two local hosts
- DA SYN flood denial-of-service attack
Show answer & explanationAnswer & explanation
Correct answer: A. ICMP tunneling used for covert data exfiltration or C2
Legitimate ICMP echo (ping) traffic normally uses small, fixed-size payloads (e.g., 32–64 bytes) sent infrequently for connectivity checks. Here, the unusually large (1400-byte), consistent-interval packets with variable, non-standard payload content sent repeatedly to an external host strongly indicate ICMP tunneling, where data is smuggled inside ICMP payloads to bypass firewalls that permit ICMP but inspect other protocols less closely.
Why the other options are wrong
- B. Monitoring pings use small, fixed payloads and infrequent probes, not 1400-byte variable data.
- C. ARP poisoning occurs at Layer 2 within the local subnet, not via ICMP to an external host.
- D. A SYN flood involves TCP SYN packets, not ICMP echo traffic.
ICMP Tunneling
A covert channel technique that encodes data inside ICMP echo request/reply payloads to exfiltrate data or maintain C2, bypassing filters that allow ICMP through.
- Legitimate pings use small, fixed payloads infrequently
- Tunneling shows large, variable, or repeated payloads
- Firewalls often permit ICMP, making it attractive for evasion
Memory trick: A 'ping' stuffed fat with data is smuggling secrets.