EC-CouncilEC-Council
312-49 · Question #234
312-49 Question #234: Real Exam Question with Answer & Explanation
Sign in or unlock 312-49 to reveal the answer and full explanation for question #234. The question stem and answer options stay visible for context.
Submitted by ashley.k· Apr 18, 2026Network Forensics
Question
An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?
Options
- ASmurf
- BPing of death
- CFraggle
- DNmap scan
Unlock 312-49 to see the answer
You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Ping of Death#ICMP attacks#Network forensics#Firewall logs