nerdexam
EC-Council

312-49 · Question #283

George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP programs without obtaining

The correct answer is B. src port 22 and dst port 22. SFTP (SSH File Transfer Protocol) operates over SSH, which uses TCP port 22. To capture only SFTP traffic in Ethereal (now Wireshark), the correct capture filter is 'src port 22 and dst port 22'. Port 23 is Telnet, not SFTP. Option C incorrectly uses UDP (SFTP/SSH uses TCP), and

Submitted by tyler.j· Apr 18, 2026Network Forensics

Question

George is the network administrator of a large Internet company on the west coast. Per corporate policy, none of the employees in the company are allowed to use FTP or SFTP programs without obtaining approval from the IT department. Few managers are using SFTP program on their computers. Before talking to his boss, George wants to have some proof of their activity. George wants to use Ethereal to monitor network traffic, but only SFTP traffic to and from his network. What filter should George use in Ethereal?

Options

  • Asrc port 23 and dst port 23
  • Bsrc port 22 and dst port 22
  • Cudp port 22 and host 172.16.28.1/24
  • Dnet port 22

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    89% (41)
  • C
    2% (1)
  • D
    2% (1)

Explanation

SFTP (SSH File Transfer Protocol) operates over SSH, which uses TCP port 22. To capture only SFTP traffic in Ethereal (now Wireshark), the correct capture filter is 'src port 22 and dst port 22'. Port 23 is Telnet, not SFTP. Option C incorrectly uses UDP (SFTP/SSH uses TCP), and option D uses invalid syntax. By filtering on port 22, George captures all SSH-tunneled traffic including SFTP sessions to and from hosts on his network, providing the proof he needs.

Topics

#Network Monitoring#Packet Analysis#SFTP#Port Numbers

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice