
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 7)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 31–35
- 31
What is the purpose of correlating multiple TCP streams in a packet capture?
Select an answer first - 32
In an Ethernet frame, which field indicates the type of payload encapsulated in the frame?
Select an answer first - 33
A security analyst receives a packet capture file with a .pcapng extension from a network device. The analyst needs to open it in Wireshark, but Wireshark reports an error. What is the most likely cause?
Select an answer first - 34
What is the purpose of the 'Follow TCP Stream' feature in Wireshark?
Select an answer first - 35
Which packet capture file format is the default output format when using tcpdump and is widely supported by many network analysis tools?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.