ExamGecko
Question list
Search
Search

Related questions











Question 210 - 200-201 discussion

Report
Export

Refer to the exhibit.

An analyst was given a PCAP file, which is associated with a recent intrusion event in the company FTP server Which display filters should the analyst use to filter the FTP traffic?

A.

dstport == FTP

Answers
A.

dstport == FTP

B.

tcp.port==21

Answers
B.

tcp.port==21

C.

tcpport = FTP

Answers
C.

tcpport = FTP

D.

dstport = 21

Answers
D.

dstport = 21

Suggested answer: B

Explanation:

The correct display filter for analyzing FTP traffic in a PCAP file is ''tcp.port==21''. This filter will show all TCP packets where the port number is 21, which is the standard port for FTP control messages.

asked 07/10/2024
Abbas Jabbari
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first