nerdexam
Cisco

300-215 · Question #2

Refer to the exhibit. An engineer is analyzing a TCP stream in a Wireshark after a suspicious email with a URL. What should be determined about the SMB traffic from this stream?

The correct answer is D. It is sharing access to files and printers. The Wireshark output shows SMB protocol transactions, including NT Create AndX Response and Write AndX Response, indicating the transfer of files or objects. SMB (Server Message Block) is a protocol used for file sharing and printer access in Windows networks. The log does not…

Submitted by rania.sa· Mar 6, 2026Cloud Security Operations & Incident Response

Question

Refer to the exhibit. An engineer is analyzing a TCP stream in a Wireshark after a suspicious email with a URL. What should be determined about the SMB traffic from this stream?

Exhibit

300-215 question #2 exhibit

Options

  • AIt is redirecting to a malicious phishing website
  • BIt is exploiting redirect vulnerability
  • CIt is requesting authentication on the user site.
  • DIt is sharing access to files and printers.

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    13% (6)
  • C
    6% (3)
  • D
    79% (38)

Explanation

The Wireshark output shows SMB protocol transactions, including NT Create AndX Response and Write AndX Response, indicating the transfer of files or objects. SMB (Server Message Block) is a protocol used for file sharing and printer access in Windows networks. The log does not indicate phishing or redirection behavior but rather normal SMB communication such as accessing files or shared resources.

Topics

#Network protocol analysis#Wireshark#SMB#Network forensics

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice