GCIH · Question #350
An analyst notices ICMP Timestamp replies sent from multiple IP addresses on a client LAN to a single IP address on another network segment within a short period of time. What is likely occurring?
The correct answer is D. Network mapping. By default, to identify which addresses are in use, Nmap sends four packets to each address in the target range, including an ICMP Timestamp request. ICMP Timestamp requests aren't used for IP spoofing or port scans. Traceroute would return Time Exceeded messages, not Timestamp
Question
An analyst notices ICMP Timestamp replies sent from multiple IP addresses on a client LAN to a single IP address on another network segment within a short period of time. What is likely occurring?
Options
- APort scanning
- BTraceroute
- CIP spoofing
- DNetwork mapping
How the community answered
(52 responses)- A2% (1)
- B10% (5)
- C4% (2)
- D85% (44)
Explanation
By default, to identify which addresses are in use, Nmap sends four packets to each address in the target range, including an ICMP Timestamp request. ICMP Timestamp requests aren't used for IP spoofing or port scans. Traceroute would return Time Exceeded messages, not Timestamp
Topics
Community Discussion
No community discussion yet for this question.