Exam 200-201 All QuestionsBrowse all questions from this exam
Question 300

Refer to the exhibit. An engineer received a ticket to analyze unusual network traffic. What is occurring?

    Correct Answer: C

    The exhibit shows repeated ICMP requests and replies between the same source and destination IP addresses, with some marked as 'Unknown ICMP (obsolete or malformed?)'. This repetitiveness and the continuous use of the ICMP protocol are indicative of a denial-of-service (DoS) attack, where excessive ICMP echo requests (ping) are often used to overwhelm the network or target host, thus disrupting normal traffic flow.

Discussion
cecb9b9Option: C

Answer should be C considering that its the same Source and Destination IP's along with the ICMP protocol being continuously used.

Andre70Option: A

I think this is data exfiltration