
CiscoCertified CyberOps Associate
Domain 4Objective 6
4.6 Extract Files from a TCP Stream When Given a PCAP File and Wireshark 200-201 Practice Questions (Page 7)
Part of the 4.0 Network Intrusion Analysis domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
20%of the exam
Questions 31–34
- 31
An analyst is analyzing a PCAP and needs to extract a file from a TCP stream that uses a protocol with a dynamic port. The analyst has identified the stream but the data appears to be compressed. What is the best approach to extract the file?
Select an answer first - 32
When you select a packet in the Packet List pane, which pane shows the decoded protocol fields of that packet?
Select an answer first - 33
When saving a followed TCP stream in Wireshark, what is the purpose of choosing the 'Raw' format?
Select an answer first - 34
What does Wireshark's 'Follow TCP Stream' feature do?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.