CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is reviewing a packet capture from a compromised host. The analyst observes a high volume of ICMP Echo Request and Echo Reply packets, but the data payload within these packets is unusually large and appears to contain encoded information, rather than typical small ping payloads. The destination IP addresses are external and belong to a known suspicious range. What type of covert communication is this indicative of?

  1. AHTTP/HTTPS Tunneling
  2. BDNS Tunneling
  3. CICMP Tunneling
  4. DTCP Port Scan
Show answer & explanation

Correct answer: C. ICMP Tunneling

ICMP tunneling (also known as 'ping tunneling') involves encapsulating data within ICMP Echo Request and Echo Reply packets to establish a covert communication channel. The key indicators here are the 'high volume of ICMP' packets, 'unusually large' data payload, and 'appears to contain encoded information', which differentiate it from normal ping traffic.

Why the other options are wrong

  • A. HTTP/HTTPS tunneling uses web traffic to encapsulate data, not ICMP.
  • B. DNS tunneling uses DNS queries/responses to encapsulate data, not ICMP.
  • D. A TCP port scan involves sending TCP packets to various ports to determine open services, not using ICMP for data transfer.

ICMP Tunneling

A covert communication method that encapsulates data from other protocols (like TCP or UDP) within the data portion of ICMP Echo Request and Echo Reply packets.

  • Bypasses firewalls that only inspect higher-layer protocols.
  • Relies on ICMP being allowed through firewalls for basic connectivity.
  • Indicators include unusually large ICMP payloads or non-standard ICMP types.

Memory trick: Covert channels hide data in plain sight.

More Security Operations questions