nerdexam
Cisco

100-160 · Question #18

You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you use? (Choose two.)

The correct answer is A. Wireshark B. tcpdump. Wireshark provides a graphical interface for packet capture and analysis. Tcpdump is a command- line tool that captures packets for detailed offline review.

Cybersecurity Incident Response

Question

You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you use? (Choose two.)

Options

  • AWireshark
  • Btcpdump
  • CNmap
  • Dnetstat

How the community answered

(38 responses)
  • A
    95% (36)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Wireshark provides a graphical interface for packet capture and analysis. Tcpdump is a command- line tool that captures packets for detailed offline review.

Topics

#Wireshark#tcpdump#packet capture#network forensics

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice