
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 3)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 11–15
- 11
A security team has been asked to provide a packet capture to an external investigator. The investigator requests a file that preserves per-interface capture details and can contain multiple interfaces. Which capture file format should the team provide?
Select an answer first - 12
A forensic analyst is reassembling a TCP stream in Wireshark and notices that the data appears to be out of order. The analyst wants to ensure the reassembled data is accurate. What should the analyst do?
Select an answer first - 13
You are investigating a suspected data exfiltration. In Wireshark, you have identified a TCP stream that appears to contain a base64-encoded payload. What is the best way to decode and inspect the payload?
Select an answer first - 14
An analyst is working with a large pcap file and needs to isolate all traffic between two specific IP addresses, but the capture also contains traffic from other hosts. The analyst wants to see only the packets between the two IPs and also reassemble the TCP streams. Which approach is most efficient?
Select an answer first - 15
An incident responder is analyzing a pcap file and finds an HTTP POST request to a suspicious URL, followed by a TCP stream containing an encoded blob. The responder needs to determine if the blob is related to the POST request. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.