
CiscoCertified CyberOps Associate
Domain 4Objective 6
4.6 Extract Files from a TCP Stream When Given a PCAP File and Wireshark 200-201 Practice Questions (Page 3)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
20%of the exam
Questions 11–15
- 11
What is the first step in carving an embedded file from a TCP stream?
Select an answer first - 12
During analysis of a TCP stream, an analyst notices the data contains a ZIP file signature (PK) but the stream also includes HTTP headers and other protocol overhead. What is the most effective way to extract the ZIP file?
Select an answer first - 13
In Wireshark, how do you open the 'Follow TCP Stream' window for a selected packet?
Select an answer first - 14
How can you quickly determine whether a TCP stream contains binary data or text in Wireshark's Follow TCP Stream window?
Select an answer first - 15
After extracting a file from a TCP stream, what is a good way to verify that the file is intact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.