Protocol Analysis WCNA - Wireshark Certified Network Analyst Practice Exam
How do you determine which Profile is in use while you are capturing traffic?
Applications may override the default port value defined in the TCP/IP stack services file.
Display filters areapplied to decrease the time required to identify the cause of poor network performance, unusual network traffic patterns or other traffic of interest.
You can identify compromised hosts that are communicating with Command and Control (C&C) servers by capturing traffic close to the network egress point and filtering on the IP addresses of the suspect C&C servers.
Which Wireshark feature is used to make the process of following TCP Sequence/Acknowledgment numbers easier to interpret?
You are analyzing network traffic, but you only see ARP queries - you do not see any ARP responses. What could cause this situation?
DNS can onlyresolve IP addresses to host names.
Which traffic characteristic is often seen when analyzing database applications that transfer individual records across the network?
What might be the purpose of thistraffic?
A host has just booted up. This host is allowed to send ARP queries for the MAC address of thelocal DNS server before sending gratuitous ARPs to test for duplicate IP addresses on the network.