Cs1202 Wireshark Exam

20 Questions | Total Attempts: 1305

SettingsSettingsSettings
Please wait...
Cs1202 Wireshark Exam

.


Questions and Answers
  • 1. 
    You can use Wireshark's Expressions to build display filters.
    • A. 

      True

    • B. 

      False

  • 2. 
    Which statement about the setting shown in the Preference window above
    • A. 

      The Microsoft device interface is hidden.

    • B. 

      Wireshark will use inverse name queries to resolve local host address to IP address.

    • C. 

      Wireshark will only capture traffic to the local adapter, broadcast, or multicast address

  • 3. 
    Which feature is only available with promiscuous mode operation?
    • A. 

      Enable an interface to capture packets that are sent to any MAC address

    • B. 

      Enable an interface to capture gratuitous ARP request/response packets

    • C. 

      Enable an interface to capture packets addressed to broadcast and multicast addresses

  • 4. 
    A custom column can be added to and rearranged in the Packet List pane.
    • A. 

      True

    • B. 

      False

  • 5. 
    Which statement about the TCP stream shown above is correct?
    • A. 

      The HTTP client requested a graphic file

    • B. 

      The HTTP server rediredted the client's request to another server.

    • C. 

      The HTTP client sent an HTTP GET request to the HTTP server

  • 6. 
    Which drive is used to capture packets when Wireshark is running on a Apple computer?
    • A. 

      Macpcap

    • B. 

      Libpcap

    • C. 

      Airpcap

  • 7. 
    Type in the name of the pcap driver used when running Wireshark on  a Windows computer
  • 8. 
    Which statement about the Capture Options window shown above is correct?
    • A. 

      Wireshark will resolve IP addresses to host

    • B. 

      Wireshark will attempt to resolve OUI values for all MAC addresses

    • C. 

      Wireshark will scroll to display the most recent packet captured

  • 9. 
    Display filters and capture filters can be interchanged because they use the same syntax.
    • A. 

      True

    • B. 

      False

  • 10. 
    Which display filter is used to display all DHCP traffic?
    • A. 

      Dhcp

    • B. 

      Tcp.port == 68

    • C. 

      Bootp

  • 11. 
    How do you quickly spot large gaps in time between packets in a trace file containing 10,000 packets?
    • A. 

      Set the Time column to Seconds Since Epoch and scroll through the trace file

    • B. 

      Open and examine the Notes section of Wireshark's Expert infos window

    • C. 

      Set the Time column to Seconds Since Previously Displayed Packet and sort the Time column

  • 12. 
    Based on the image shown above, Wireshark's time display format is set to Seconds Since Beginning of Capture.
    • A. 

      True

    • B. 

      False

  • 13. 
    Which of these filters can be used as either a capture or display filter?
    • A. 

      Dns

    • B. 

      Udp

    • C. 

      Dhcp

  • 14. 
    When you select Prepare a filter, the filter is immediately applied to the traffice
    • A. 

      True

    • B. 

      False

  • 15. 
    The following capture filter will capture all FTP traffic on port 21 regardless of the destination or source host. host www.wiresharkbook.com && port 21
    • A. 

      True

    • B. 

      False

  • 16. 
    Which statement about capture filters is correct?
    • A. 

      Capture filters can be applied after the capture process begins

    • B. 

      Capture filters can be applied while you are opening a trace file

    • C. 

      Wireshark includes a default set of capture filters

  • 17. 
    Which Display filter will show only packets for the source address of 192.168.0.25?
    • A. 

      Ip.addr == 192.168.0.25 src

    • B. 

      Ip.src == 192.168.0.25

    • C. 

      !ip.src == 192.168.0.25

  • 18. 
    Which display filter operator is the equivalent of AND?
    • A. 

      $$

    • B. 

      &&

    • C. 

      ||

  • 19. 
    This display filter would remove all packet destined for host 10.0.0.5 ip.dst == 10.100.0.5!
    • A. 

      True

    • B. 

      False

  • 20. 
    Both of the the display filters below will provide the same output.   ip.dst==10.100.0.1 or ip.dst==10.100.0.1   ip.dst==10.100.0.1 || ip.dst==10.100.0.1  
    • A. 

      True

    • B. 

      False

Back to Top Back to top