Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 23

2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
9concepts
30%of the exam

Questions 16–20

  1. 16expert · medium

    A security analyst is investigating a suspected data breach. The pcap file shows an internal host making an HTTPS connection to an external IP on port 443, followed by a series of DNS TXT queries to a domain known for data exfiltration. The analyst needs to determine if the HTTPS connection and the DNS queries are related. Which approach is most effective?

    Select an answer first
  2. 17application · medium

    An analyst is examining a pcap file and needs to find all packets that contain the string 'password' in the payload. Which Wireshark display filter should the analyst use?

    Select an answer first
  3. 18application · medium

    An analyst is investigating a DNS exfiltration incident. The capture shows many DNS queries to an external domain, each with a subdomain that appears to be base64-encoded data. The analyst needs to reconstruct the exfiltrated data. What is the most effective approach?

    Select an answer first
  4. 19expert · hard

    You are analyzing a pcap from a compromised host. You find an HTTP POST to a known malicious domain with a filename 'update.exe' in the Content-Disposition header. You also see a subsequent TCP stream that contains binary data with a MZ header. What is the most likely scenario?

    Select an answer first
  5. 20application · medium

    A network analyst is investigating a malware infection and has a pcap file. The analyst needs to reassemble the entire TCP conversation between the infected host and the command-and-control server to see the full payload. Which Wireshark feature should the analyst use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.