Quiz : How Well Do You Know Wireshark?

20 Questions | Attempts: 3938
Share

SettingsSettingsSettings
Quiz : How Well Do You Know Wireshark? - Quiz

Wireshark is an open-source, free packet analyzer. How well do you know about it? The program is mainly used for analysis, troubleshooting, education, software, and communications protocol development, etc. Are you well aware of the intricate details of this software? Well then, let's test your knowledge with a super fun quiz! Just answer a few questions, and you will get your scores immediately! You are expected to answer all the questions. Keep learning and have fun!


Questions and Answers
  • 1. 
    You can use Wireshark's Expressions to build display filters.
    • A. 

      True

    • B. 

      False

  • 2. 
      Which statement about the setting shown in the Preference window above
    • A. 

      The Microsoft device interface is hidden.

    • B. 

      Wireshark will use inverse name queries to resolve local host address to IP address.

    • C. 

      Wireshark will only capture traffic to the local adapter, broadcast, or multicast address

    • D. 

      None of the above

  • 3. 
    Which feature is only available with promiscuous mode operation?
    • A. 

      Enable an interface to capture packets that are sent to any MAC address

    • B. 

      Enable an interface to capture gratuitous ARP request/response packets

    • C. 

      Enable an interface to capture packets addressed to broadcast and multicast addresses

  • 4. 
    A custom column can be added to and rearranged in the Packet List pane.
    • A. 

      True

    • B. 

      False

  • 5. 
    Which statement about the TCP stream shown above is correct?
    • A. 

      The HTTP client requested a graphic file

    • B. 

      The HTTP server rediredted the client's request to another server.

    • C. 

      The HTTP client sent an HTTP GET request to the HTTP server

    • D. 

      None of the above

  • 6. 
    Which drive is used to capture packets when Wireshark is running on a Apple computer?
    • A. 

      Macpcap

    • B. 

      Libpcap

    • C. 

      Airpcap

  • 7. 
    Type in the name of the pcap driver used when running Wireshark on  a Windows computer
  • 8. 
    Which statement about the Capture Options window shown above is correct?
    • A. 

      Wireshark will resolve IP addresses to host

    • B. 

      Wireshark will attempt to resolve OUI values for all MAC addresses

    • C. 

      Wireshark will scroll to display the most recent packet captured

  • 9. 
    Display filters and capture filters can be interchanged because they use the same syntax.
    • A. 

      True

    • B. 

      False

  • 10. 
    Which display filter is used to display all DHCP traffic?
    • A. 

      Dhcp

    • B. 

      Tcp.port == 68

    • C. 

      Bootp

  • 11. 
    How do you quickly spot large gaps in time between packets in a trace file containing 10,000 packets?
    • A. 

      Set the Time column to Seconds Since Epoch and scroll through the trace file

    • B. 

      Open and examine the Notes section of Wireshark's Expert infos window

    • C. 

      Set the Time column to Seconds Since Previously Displayed Packet and sort the Time column

  • 12. 
    Based on the image shown above, Wireshark's time display format is set to Seconds Since Beginning of Capture.
    • A. 

      True

    • B. 

      False

  • 13. 
    Which of these filters can be used as either a capture or display filter?
    • A. 

      Dns

    • B. 

      Udp

    • C. 

      Dhcp

  • 14. 
    When you select Prepare a filter, the filter is immediately applied to the traffice
    • A. 

      True

    • B. 

      False

  • 15. 
    The following capture filter will capture all FTP traffic on port 21 regardless of the destination or source host. host www.wiresharkbook.com && port 21
    • A. 

      True

    • B. 

      False

  • 16. 
    Which statement about capture filters is correct?
    • A. 

      Capture filters can be applied after the capture process begins

    • B. 

      Capture filters can be applied while you are opening a trace file

    • C. 

      Wireshark includes a default set of capture filters

    • D. 

      None of the above

  • 17. 
    Which Display filter will show only packets for the source address of 192.168.0.25?
    • A. 

      Ip.addr == 192.168.0.25 src

    • B. 

      Ip.src == 192.168.0.25

    • C. 

      !ip.src == 192.168.0.25

  • 18. 
    Which display filter operator is the equivalent of AND?
    • A. 

      $$

    • B. 

      &&

    • C. 

      ||

  • 19. 
    This display filter would remove all packet destined for host 10.0.0.5 ip.dst == 10.100.0.5!
    • A. 

      True

    • B. 

      False

  • 20. 
    Both of the the display filters below will provide the same output.   ip.dst==10.100.0.1 or ip.dst==10.100.0.1   ip.dst==10.100.0.1 || ip.dst==10.100.0.1  
    • A. 

      True

    • B. 

      False

Back to Top Back to top
×

Wait!
Here's an interesting quiz for you.

We have other quizzes matching your interest.