Browse all practice questions for the Wireshark Block 5 Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Wireshark Block 5 Practice Exam course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which menu path would you use to create and save a display filter macro for reuse?
  • Which display filter shows packets where 192.168.1.2 is the source address?
  • Which display filter shows TLS certificate handshake messages?
  • Which specific HTTP status code is most commonly used to indicate a successful request?
  • Which path in Wireshark would you use to export a summary of captures to CSV?
  • Which OS does Windows NT 5.2 map to? (rephrased)
  • How do you add a protocol-specific color rule for a particular host?
  • Which path specifically displays SSL segments on the same SSL connection as a selected packet?
  • Which menu option adds the selected protocol item in the packet details pane as a column in the packet list?
  • If you write ip.addr==A and ip.addr==B, what is required for a match?
  • How do you enable TCP reassembly in Wireshark?
  • How do you capture on a specific interface in Wireshark?
  • If the server fails to fulfill a seemingly valid request due to a server error, which HTTP status code class should be used?
  • Which sequence describes the TLS 1.2 handshake in the typical flow?
  • Which pane shows the raw data of the packet in hexadecimal and ASCII?
  • The Android 4.4 UA example belongs to which category?
  • Which configuration describes Linux running on an i686 user space on a 64-bit x86_64 CPU?
  • In Wireshark, what is the difference between a frame and a packet?
  • Which menu item applies a conversation filter for various protocols?
  • Which sequence marks the TCP four-way handshake used to terminate a connection?
  • Which operator matches either of two conditions in a display filter?
  • What is the start-of-image marker sequence commonly associated with JPEG files?
  • TTL 254 maps to which operating system family in the dataset?
  • The signature MZ is associated with which file type?
  • Which UI element displays a hierarchical tree of protocol statistics?
  • Which HTTP status code class indicates a successful request?
  • Which TLS handshake message from the server conveys its identity via certificate?
  • What does the display filter tcp.analysis.retransmission show?
  • What is the frame time delta from previous frame used for?
  • Which menu path shows statistics about the endpoints captured?
  • When saving the extracted data for a JPEG file, which extension should you use?
  • Which TLS handshake messages are optional in a typical TLS 1.2 handshake?
  • Which feature lets you view the full content of a TCP conversation by concatenating packet data?
  • Which option lets you manually assign a protocol to a selected packet in Wireshark?
  • What Wireshark feature maps MAC addresses to hardware manufacturers?
  • Windows NT 10 corresponds to which Windows version?
  • Which action displays the conversation in a human readable format with client requests in red and server responses in blue?
  • Which two messages complete the TLS 1.2 handshake before encrypted application data is exchanged?
  • The rv:41.0 UA example belongs to which category?
  • Which filter targets HTTP requests in Wireshark?
  • Which menu item allows the user to enable/disable protocol dissectors?
  • Which expression allows filtering by protocol name rather than a port or IP?
  • Which display filter would show only DNS query types?
  • What is the standard sequence of packets in the TCP three-way handshake?
  • How can you tell if DNS queries are using UDP or TCP?
  • Which display filter shows only DNS responses?
  • If you know the PSK, how do you decrypt WPA/WPA2 traffic in Wireshark?
  • Which technique is defined as sending transmissions to end nodes and analyzing responses to identify information about the communications system?
  • Which of the following best describes the observable behavior indicating a port scan?
  • Windows NT 6.2 corresponds to which Windows version?
  • Which element do you use to quickly filter displayed packets by entering a condition?
  • If a server cannot fulfill a request due to bad syntax, which HTTP status code class is most appropriate?
  • TLS version 1.2 corresponds to which hex value in the tls.version field?
  • How do you identify packet loss in a TCP trace using Wireshark?
  • What capture mode is typically required to inspect 802.11 frames in Wireshark?
  • Which HTTP status code class indicates that further action is needed by the client to fulfill the request (redirection)?
  • Which of the following is an indicator that port scanning is being performed?
  • Which IP header indicators are used to identify fragments for reassembly?
  • What tactic is used to gather information about a network by sending transmissions and analyzing responses?
  • Which statement correctly identifies the role of the first three bytes of a MAC address?
  • Which statement best describes the TCP three-way handshake?
  • In the first line of an HTTP request, which elements are present?
  • What is the purpose of 'Follow TCP Stream' in Wireshark?
  • How can TLS traffic be decrypted using a pre-master secret log file in Wireshark?
  • What capture filter would drop all ARP traffic during capture?
  • Which HTTP headers can indicate the size of the response payload?
  • Which statement is true about TTL mappings in the dataset?
  • Which Wireshark feature shows per-protocol data volumes and packet counts?
  • Which path opens a window showing all the SSL segments on the same SSL connection as a selected packet?
  • A TTL value of 64 is commonly associated with which OS family in this material?
  • Which file format is considered modern and provides richer metadata for captures?
  • Which Wireshark field shows the server certificate’s signature algorithm during the TLS handshake?
  • Which modern word processing format is a ZIP container and typically identified by a ZIP local header?
  • Which toolbar allows you to type filter expressions on the fly to filter packets?
  • TTL value associated with Solaris / AIX in the dataset?
  • Which display filter isolates DNS query names?
  • Which UI element opens files, starts captures, and changes preferences?
  • Windows NT 6.3 corresponds to which Windows version?
  • Which path opens a window showing all UDP segments on the same UDP connection as a selected packet?
  • Which filter specifically targets HTTP responses in Wireshark?
  • Which device categories are associated with Android user-agent entries in the material?
  • According to the material, what does a User-Agent string in HTTP/1.1 convey to the server?
  • Which Windows NT version maps to Windows 8.1?
  • Which signature is characteristic of a 7z archive header?
  • What does selecting Follow UDP Stream do?
  • TTL 255 maps to which operating system?
  • What does ip.addr==192.168.1.0/24 filter represent?
  • Is port scanning easy for the adversary?
  • Which items does the Expert Info window collect to highlight issues?
  • Which menu item opens the dialog to create and save display filter macros?
  • A data sample begins with the ASCII marker JFIF and includes a JPEG start-of-image sequence. The file is most likely which type?
  • Which area shows the Source and Destination addresses, along with the protocol and general information for each packet?
  • What does the Time Delta column show in the packet list?
  • Which operator matches a substring within data fields?
  • Which vendor is associated with MAC address 00:02:78:--:--:--?
  • Using the OR operator between two IP address checks, what traffic is included?
  • Why are high-volume port scans often ignored by defenders?
  • Which HTTP status code class indicates the request has been received and the server will continue processing?
  • How can you view HTTP/2 frames in Wireshark?
  • Which statement about TLS key log files is true?
  • Which pane shows the packet in hexadecimal along with the ASCII representation?
  • What does the filter !ip.addr==192.168.1.2 select?
  • What is the exact 8-byte signature that identifies a PNG file?
  • Which frames indicate a WPA2 4-way handshake for decryption?
  • Which TLS field would you inspect to see the chosen cipher suite?
  • What is the difference between 'Follow HTTP Stream' and 'Follow TLS Stream'?
  • Which Android user-agent category corresponds to rv values of 41.0 and Firefox 41.0?
  • If you want to isolate all packets belonging to a single TCP connection in Wireshark, which technique would you use?
  • Which display filter shows only HTTP GET requests?
  • What does the Time column indicate for SYN connection attempts that occur in under a second?
  • Which HTTP status code class represents redirection?
  • Why are coloring rules used in Wireshark?
  • Which pane provides a hierarchical display of very detailed information for a single packet?
  • Where in Wireshark would you configure the 802.11 WPA-PSK decryption key?
  • Which pane displays a list of packets as they are captured by the interface?
  • What is the main difference between capture filters and display filters in Wireshark?
  • For RSA-based TLS decryption in Wireshark, what must be true about the key exchange mechanism?
  • Which display filter in Wireshark selects packets belonging to a specific TCP stream by index?
  • What steps are required to decrypt TLS 1.2 traffic using private keys (RSA) in Wireshark?
  • How would you reassemble chunked HTTP responses in Wireshark?
  • Which Wireshark feature helps analyze protocol distribution in a capture?
  • What is the primary purpose of the Decode As feature in Wireshark?
  • Where can you find the list of conversations between two endpoints?
  • Which display filter shows all traffic involving IP address 192.168.1.2?
  • Which bar runs across the bottom showing the location of the saved file, packet count, and active profile?
  • What term describes frequent SYN connection attempts to a range of destination ports in a short time?
  • Which path allows decrypting the SSL stream if a key is available?
  • To view FTP credentials like username and password within a packet, which Wireshark feature is used?
  • In Wireshark, which action saves the payload bytes of a selected packet to a file?
  • Which sequence describes the steps to extract a JPEG from a capture in Wireshark?
  • Which unit best describes a frame, the basic capture element at the link layer?
  • Which term denotes the portion of a MAC address used to identify the NIC's vendor?
  • What is the function of the Expert Info window in Wireshark?
  • How can you identify potential DNS tunneling in a capture?
  • Which path opens a window showing all the TLS segments on the same TLS connection as a selected packet?
  • Which Wireshark feature provides a quick summary of protocol counts and traffic volumes?
  • To filter by a protocol such as HTTP, you should:
  • Which Linux desktop architecture is described as 64-bit in the material?
  • Which operating system architecture is listed for Apple hardware in the material?
  • What is the effect of HTTP/1.1 persistent connections?
  • Which menu item changes the current display filter and applies the changed filter immediately?
  • What is the purpose of the Follow HTTP Stream feature?
  • Which Windows version corresponds to Windows NT 5.1?
  • In Wireshark, which action displays the HTTP conversation for a specific TCP stream and results in a display filter like tcp.stream eq <n>?
  • How can you export a summary of captures to CSV?
  • Which menu item opens the dialog to create and edit display filters that you can save for later use?
  • Which action displays the conversation in a human readable format for UDP traffic?
  • What capability does the 'Display Filters' dialog provide?
  • Which data stream type is NOT listed as followable in Wireshark in the material?
  • Which path opens a window displaying all TCP segments on the same TCP connection as a selected packet?
  • Which Wireshark feature reconstructs the data stream for a TCP connection and shows the conversation?
  • Which option helps determine the actual HTTP response size when the header does not show Content-Length?
  • Which component displays a list of conversations (traffic between two endpoints)?
  • Which hex sequence identifies a PNG file signature?
  • Which of the following is NOT listed as a followable data stream type in Wireshark in the material?
  • In Wireshark display filters, what does ip.src==192.168.1.2 select?
  • A TTL value of 128 is commonly associated with which OS family in this material?
  • Which display filter shows only DNS responses?
  • Which Android user-agent category corresponds to rv values of 40.0 and Firefox 40.0?
  • Which path opens a window showing all the HTTP segments on the same HTTP connection as a selected packet?
  • Which component helps you see protocol usage statistics across the capture, such as protocol hierarchy?
  • What is PCAP-NG and why might you choose it?
  • Which path specifically displays TLS segments on the same TLS connection as a selected packet?
  • If no key is available, how will the SSL stream be displayed?
  • Which Statistics view displays a hierarchical tree of protocol statistics?
  • Which traffic does tcp.port==80 match?
  • What does the 'Display Filter Macros' feature let you do?
  • The Mac OS X mapping indicates which CPU architecture?
  • How do you export a list of conversations or endpoints from a capture?
  • How is a typical GET request line formatted in HTTP?
  • Which statement is true about capture filters in Wireshark?
  • Are port scans detectable by common defenses?
  • How can you compare throughput or data volume across two captures in Wireshark?
  • Windows NT 6.0 corresponds to which Windows version?
  • Which path opens the HTTP export dialog in Wireshark?
  • Which UI element provides general information about the current capture file?
  • During port scanning, what type of information is commonly identified?
  • Which entry represents a 64-bit Linux desktop environment?
  • How do you extract embedded HTTP objects using Wireshark?
  • Which HTTP header is used to distinguish virtual hosts when multiple domain names share a single IP address?
  • What does the display filter tcp.analysis.ack_rtt indicate?
  • What information does the Packet Bytes pane display?
  • Which line describes Mac OS X running on PowerPC?
  • The header 25 50 44 46 corresponds to which file type?
  • The ASCII bytes 57 69 6E 5A 69 70 correspond to which string commonly seen in archives?
  • How would you spot a large HTTP response with a small header?
  • Under which tactic is port scanning categorized in the given framework?
  • How would you identify a TCP retransmission in Wireshark?
  • Which sequence represents the TCP four-way handshake for connection termination?
  • Which dialog opens with expert information about the captured packets?
  • Which menu item allows forcing Wireshark to decode packets as a particular protocol?
  • How would you verify that a DNS response matches a particular query ID?
  • Which display filter filters traffic to or from 10.0.0.5?
  • Windows NT 5.1 maps to which OS?
  • Windows NT 5.2 maps to which OS?
  • Which term describes the orderly termination of a TCP connection?
  • Which option is used to reassemble out-of-order TCP segments in Wireshark?
  • Which filter would match frames containing common file types like pdf or zip?
  • In Wireshark display filters, ip.dst==192.168.1.2 selects:
  • Which display filter filters traffic to the host 1.2.3.4 on port 443?
  • Which hex sequence identifies a ZIP local file header signature?
  • How would you view and analyze IP fragmentation in Wireshark?
  • What does the tcp.stream index represent?
  • Which view shows the TLS handshake and, if decrypted, the HTTP payload?
  • Which path specifically displays HTTP segments on the same HTTP connection as a selected packet?
  • Which field would you filter on to show TLS version 1.2 traffic?
  • How would you spot IPv6 traffic in a capture?
  • Which operator is used to require both conditions in a display filter?
  • How can you identify the TLS server name used for SNI in Wireshark?
  • Windows NT 6.1 corresponds to which Windows version?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy