Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 23

2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 1)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
9concepts
30%of the exam

Questions 1–5

  1. 1foundation · easy

    Which Wireshark feature allows you to view the raw bytes of a selected packet in both hexadecimal and ASCII representation?

    Select an answer first
  2. 2foundation · easy

    When dissecting a DNS packet in Wireshark, which field indicates the number of questions in the DNS query?

    Select an answer first
  3. 3application · medium

    You have a large pcapng file and need to focus on a single conversation between two IP addresses over port 445. Which Wireshark display filter shows only that TCP conversation?

    Select an answer first
  4. 4foundation · easy

    Which Wireshark display filter would you use to show only packets that use TCP port 443?

    Select an answer first
  5. 5expert · hard

    You have two capture files: one in pcap format and one in pcapng format. You need to merge them into a single file for analysis. Which approach is most reliable?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.