Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 4Objective 6

4.6 Extract Files from a TCP Stream When Given a PCAP File and Wireshark 200-201 Practice Questions (Page 7)

Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
8concepts
20%of the exam

Questions 31–34

  1. 31expert · hard

    An analyst is analyzing a PCAP and needs to extract a file from a TCP stream that uses a protocol with a dynamic port. The analyst has identified the stream but the data appears to be compressed. What is the best approach to extract the file?

    Select an answer first
  2. 32foundation · easy

    When you select a packet in the Packet List pane, which pane shows the decoded protocol fields of that packet?

    Select an answer first
  3. 33foundation · easy

    When saving a followed TCP stream in Wireshark, what is the purpose of choosing the 'Raw' format?

    Select an answer first
  4. 34foundation · easy

    What does Wireshark's 'Follow TCP Stream' feature do?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 200-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.