CV0-003 · Question #106
An administrator is attempting to troubleshoot an issue between a web server in the DMZ and an internal workstation by reviewing packet captures. Upon inspection, the payloads of the packets are…
The correct answer is A. The administrator has yet to authenticate to the network. In enterprise environments, certain network monitoring platforms, SSL/TLS inspection appliances, or secure network segments require the administrator to authenticate before decrypted packet data is accessible. Without the proper credentials or session token, the capture tool…
Question
An administrator is attempting to troubleshoot an issue between a web server in the DMZ and an internal workstation by reviewing packet captures. Upon inspection, the payloads of the packets are unreadable. Which of the following could be the cause of this issue?
Options
- AThe administrator has yet to authenticate to the network
- BThe sniffer is located on an incorrect subnet
- CA vulnerability scanner has interfered with the packet capture
- DEnd-to-end encryption is applied on the network
How the community answered
(51 responses)- A78% (40)
- B6% (3)
- C14% (7)
- D2% (1)
Explanation
In enterprise environments, certain network monitoring platforms, SSL/TLS inspection appliances, or secure network segments require the administrator to authenticate before decrypted packet data is accessible. Without the proper credentials or session token, the capture tool may still collect packets but will display only the encrypted payload, which appears unreadable. This is a correctable access issue specific to the administrator's session state. While end-to-end encryption (D) is also a valid cause of unreadable payloads, it represents a permanent architectural condition that would always be visible - not a troubleshooting variable the admin can resolve. The question asks for a cause of the issue, pointing toward the authentication gap as the actionable root cause.
Topics
Community Discussion
No community discussion yet for this question.