200-201 exam dumps

200-201 practice question 261 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 261

Select 3

You are investigating a potential data breach and have been provided with a PCAP file containing suspicious network traffic. Using Wireshark, you need to extract a file transferred via HTTP in the TCP stream. Which of the following steps should be performed to extract the file successfully?

  1. A

    Use the 'Follow TCP Stream' option in Wireshark to view the raw data of the TCP connection.

  2. B

    Identify the correct TCP stream by filtering the traffic using 'http' as the display filter.

  3. C

    Export the file directly by right-clicking on the packet and selecting 'Export File'.

  4. D

    Reassemble the HTTP object by using the 'File > Export Objects > HTTP' option in Wireshark.

  5. E

    Enable 'TCP Stream Reassembly' in the Wireshark preferences before analyzing the traffic.

Show answer and explanation

Correct answers: A, B, D

Explanation

To extract files from a TCP stream in Wireshark, you need to first identify the correct TCP stream (e.g., by filtering traffic for HTTP connections) and then use the 'Follow TCP Stream' option to analyze the data. Once identified, the file can be reassembled and extracted using the 'Export Objects > HTTP' option. These steps ensure that the transferred file is properly retrieved from the captured network traffic.

  • A. Correct.

    Correct. The 'Follow TCP Stream' option allows you to view the data exchanged in the TCP connection, which is critical for identifying and extracting the file.

  • B. Correct.

    Correct. Filtering the traffic using 'http' as a display filter helps narrow down the packets associated with HTTP traffic, making it easier to find the relevant TCP stream.

  • C. Incorrect.

    Incorrect. There is no direct option to 'Export File' by right-clicking on a packet in Wireshark. Files must be extracted through HTTP object reassembly or similar methods.

  • D. Correct.

    Correct. The 'Export Objects > HTTP' option allows you to extract reassembled HTTP objects directly from the captured traffic, which is necessary to retrieve the file.

  • E. Incorrect.

    Incorrect. While TCP Stream Reassembly is important, it is enabled by default in Wireshark and does not require manual configuration in most cases.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam