nerdexam
GIAC

GCIH · Question #350

An analyst notices ICMP Timestamp replies sent from multiple IP addresses on a client LAN to a single IP address on another network segment within a short period of time. What is likely occurring?

The correct answer is D. Network mapping. By default, to identify which addresses are in use, Nmap sends four packets to each address in the target range, including an ICMP Timestamp request. ICMP Timestamp requests aren't used for IP spoofing or port scans. Traceroute would return Time Exceeded messages, not Timestamp

Reconnaissance, Scanning, and Enumeration

Question

An analyst notices ICMP Timestamp replies sent from multiple IP addresses on a client LAN to a single IP address on another network segment within a short period of time. What is likely occurring?

Options

  • APort scanning
  • BTraceroute
  • CIP spoofing
  • DNetwork mapping

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    10% (5)
  • C
    4% (2)
  • D
    85% (44)

Explanation

By default, to identify which addresses are in use, Nmap sends four packets to each address in the target range, including an ICMP Timestamp request. ICMP Timestamp requests aren't used for IP spoofing or port scans. Traceroute would return Time Exceeded messages, not Timestamp

Topics

#ICMP timestamp#network mapping#host discovery#traffic analysis

Community Discussion

No community discussion yet for this question.

Full GCIH Practice