Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CheckPoint 156-582 Exam - Topic 6 Question 25 Discussion

Is it possible to analyze ICMP packets with tcpdump?
A) Yes, tcpdump is not limited to TCP specific issues
B) No, use fw monitor instead
C) No, tcpdump works from layer 4. ICMP is located in the network layer (layer 3), therefore is not applicable to this scenario
D) No, since ICMP does not have any source or destination ports, but specification of port numbers is mandatory

CheckPoint 156-582 Exam - Topic 6 Question 25 Discussion

Actual exam question for CheckPoint's 156-582 exam
Question #: 25
Topic #: 6
[All 156-582 Questions]

Is it possible to analyze ICMP packets with tcpdump?

Show Suggested Answer Hide Answer
Suggested Answer: A

Yes, it is possible to analyze ICMP packets with tcpdump. While tcpdump is often associated with capturing TCP packets, it is not limited to them and can capture and analyze any protocol that traverses the network, including ICMP, which operates at Layer 3 (Network Layer) of the OSI model. ICMP packets do not use ports, but tcpdump can filter and display these packets based on other criteria such as type and code fields.


Contribute your Thoughts:

0/2000 characters
Bette
24 days ago
I feel like I've seen a similar question before, and it was about tcpdump being able to capture all types of packets, including ICMP.
upvoted 0 times
...
Rochell
29 days ago
I'm not so sure about that. I thought tcpdump was limited to certain protocols, but I can't recall the details.
upvoted 0 times
...
Becky
1 month ago
I think tcpdump can analyze ICMP packets since it's not just for TCP, right? I remember practicing that in class.
upvoted 0 times
...

Save Cancel