Cisco
100-160 · Question #18
You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you use? (Choose two.)
The correct answer is A. Wireshark B. tcpdump. Wireshark provides a graphical interface for packet capture and analysis. Tcpdump is a command- line tool that captures packets for detailed offline review.
Cybersecurity Incident Response
Question
You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you use? (Choose two.)
Options
- AWireshark
- Btcpdump
- CNmap
- Dnetstat
How the community answered
(38 responses)- A95% (36)
- C3% (1)
- D3% (1)
Explanation
Wireshark provides a graphical interface for packet capture and analysis. Tcpdump is a command- line tool that captures packets for detailed offline review.
Topics
#Wireshark#tcpdump#packet capture#network forensics
Community Discussion
No community discussion yet for this question.