
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 9)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 41–45
- 41
A colleague provides you with a capture file that has a .pcapng extension. You need to open it in Wireshark, but the tool reports an error. Which action is most appropriate?
Select an answer first - 42
A security analyst is investigating a multi-stage attack. The pcap file shows: (1) an HTTP request to a URL with a long query string, (2) a TCP stream containing a binary file, and (3) a DNS query for a domain that matches the URL's hostname. The analyst needs to determine the relationship between these events. Which approach is most effective?
Select an answer first - 43
You are analyzing a pcap file and need to extract a file that was transferred over HTTP. You have already used 'Follow TCP Stream' and see binary data. What is the most efficient next step to recover the file?
Select an answer first - 44
In a pcap, you see a series of TCP packets with the same sequence number but different payloads. What does this indicate?
Select an answer first - 45
In a TCP segment, which field is used to identify the application protocol that the segment carries?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.