
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 10)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 46–50
- 46
Which characteristic is unique to the pcapng format compared to the older pcap format?
Select an answer first - 47
While analyzing a pcapng file in Wireshark, you need to isolate only the packets that contain HTTP responses with a 500-series status code. Which display filter accomplishes this?
Select an answer first - 48
In a packet capture, you see a UDP packet with a source port of 53 and a destination port of 53. The packet contains a DNS response with a large number of records. What is the most likely explanation?
Select an answer first - 49
Which Wireshark feature automatically reassembles TCP streams for display?
Select an answer first - 50
You are investigating a pcap and need to find all packets that are part of a TCP conversation where the initial SYN packet had a window size of 65535. You have identified the SYN packet. What is the most efficient way to isolate the entire conversation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.