
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 5)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 21–25
- 21
In a packet capture, you notice a series of TCP packets with the SYN flag set and the ACK flag clear, all from the same source IP to various destination ports on a single host. The destination host responds with RST packets. What does this pattern most likely indicate?
Select an answer first - 22
A security analyst is analyzing a pcap file and sees a packet with an IP header that has a protocol field value of 6. What does this indicate?
Select an answer first - 23
Which of the following is an example of a suspicious pattern that might indicate malicious activity in a packet capture?
Select an answer first - 24
During a forensic analysis, an analyst extracts a file from an HTTP stream and notices that the file has a .exe extension but the magic bytes are 'MZ'. What should the analyst conclude?
Select an answer first - 25
Which Wireshark feature allows you to export files that were transferred over HTTP from a packet capture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.