Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 6

4.6 Extract Files from a TCP Stream When Given a PCAP File and Wireshark 200-201 Practice Questions (Page 1)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
8concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    An analyst is investigating a PCAP that contains multiple HTTP sessions. The analyst needs to isolate the TCP stream that carried a specific file download. The analyst knows the client IP address and the server IP address. Which Wireshark filter should the analyst apply to narrow down the packets to that specific TCP stream?

    Select an answer first
  2. 2foundation · easy

    Which Wireshark display filter would you use to show only packets belonging to a specific TCP stream, assuming the stream index is 5?

    Select an answer first
  3. 3application · medium

    An analyst is following a TCP stream in Wireshark and sees a mix of readable text and binary characters. The analyst needs to extract the data for further analysis. What should the analyst do to determine whether the stream is primarily text or binary?

    Select an answer first
  4. 4expert · hard

    An analyst is investigating a PCAP and finds a TCP stream that contains a file transfer. The stream includes a file signature for a RAR archive, but the file is fragmented across multiple TCP segments. What is the best approach to extract the RAR file?

    Select an answer first
  5. 5application · easy

    An analyst is investigating a PCAP and needs to view the full contents of a TCP conversation that includes a file transfer. The analyst wants to see the reassembled data in a single view. Which Wireshark feature should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.