Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 6

4.6 Extract Files from a TCP Stream When Given a PCAP File and Wireshark 200-201 Practice Questions (Page 2)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
8concepts
20%of the exam

Questions 6–10

  1. 6foundation · easy

    What is a PCAP file?

    Select an answer first
  2. 7application · medium

    An analyst follows a TCP stream in Wireshark and the data appears as readable ASCII text with occasional binary characters. The analyst needs to extract the data for further analysis. What is the best approach?

    Select an answer first
  3. 8application · medium

    An analyst has followed a TCP stream in Wireshark and identified that it contains a file transfer. The analyst needs to save the raw data of the stream to a file for further analysis. Which action should the analyst take?

    Select an answer first
  4. 9foundation · easy

    How can you quickly identify all packets that belong to the same TCP connection in Wireshark?

    Select an answer first
  5. 10application · medium

    An analyst is working with a PCAP that contains multiple TCP streams. The analyst needs to identify which stream contains a specific file transfer. What is the most efficient way to find the correct stream?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.