ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 50 - CS0-003 discussion

Report
Export

A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself. Which of the following can the analyst perform to see the entire contents of the downloaded files?

A.
Change the display filter to f cp. accive. pore
Answers
A.
Change the display filter to f cp. accive. pore
B.
Change the display filter to tcg.port=20
Answers
B.
Change the display filter to tcg.port=20
C.
Change the display filter to f cp-daca and follow the TCP streams
Answers
C.
Change the display filter to f cp-daca and follow the TCP streams
D.
Navigate to the File menu and select FTP from the Export objects option
Answers
D.
Navigate to the File menu and select FTP from the Export objects option
Suggested answer: C

Explanation:

The best way to see the entire contents of the downloaded files in Wireshark is to change the display filter to ftp-data and follow the TCP streams. FTP-data is a protocol that is used to transfer files between an FTP client and server using TCP port 20. By filtering for ftp-data packets and following the TCP streams, the analyst can see the actual file data that was transferred during the FTP session

asked 02/10/2024
Amar Lojo
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first