Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 100-160 Exam - Topic 1 Question 4 Discussion

You are collecting data after a suspected intrusion on the local LAN.You need to capture incoming IP packets to a file for an investigator to analyze.Which two tools should you use? (Choose 2.)
A) Wireshark and B) tcpdump
C) Nmap
D) netstat

Cisco 100-160 Exam - Topic 1 Question 4 Discussion

Actual exam question for Cisco's 100-160 exam
Question #: 4
Topic #: 1
[All 100-160 Questions]

You are collecting data after a suspected intrusion on the local LAN.

You need to capture incoming IP packets to a file for an investigator to analyze.

Which two tools should you use? (Choose 2.)

Show Suggested Answer Hide Answer
Suggested Answer: A, B

The CCST Cybersecurity Study Guide specifies that both Wireshark and tcpdump are packet capture tools that can record network traffic to a file for later analysis.

'Wireshark provides a graphical interface for packet capture and analysis. Tcpdump is a command-line tool that captures packets for detailed offline review.'

(CCST Cybersecurity, Incident Handling, Network Traffic Analysis section, Cisco Networking Academy)

A is correct: Wireshark is widely used for packet capture and analysis.

B is correct: tcpdump is a CLI-based packet capture tool.

C (Nmap) is for network scanning, not packet capture.

D (netstat) displays network connections and ports but does not capture packets.


Contribute your Thoughts:

0/2000 characters
Sabra
8 months ago
Really? I thought there were other options out there.
upvoted 0 times
...
Amie
9 months ago
Agreed, those are the go-to tools for packet capture.
upvoted 0 times
...
Kattie
9 months ago
Definitely Wireshark and tcpdump!
upvoted 0 times
...
Chu
9 months ago
Wait, isn’t Nmap also useful for this?
upvoted 0 times
...
Ben
9 months ago
No way, netstat won't capture packets like those two.
upvoted 0 times
...
Aleisha
9 months ago
I practiced a similar question before, and I think both Wireshark and tcpdump were the answers. I hope I remember that correctly!
upvoted 0 times
...
Rolland
10 months ago
I feel like Nmap is more for network scanning rather than capturing packets, so I don't think it fits this scenario.
upvoted 0 times
...
Meaghan
10 months ago
I'm not entirely sure, but I remember tcpdump being mentioned in class as a command-line tool for capturing packets. It might be a good choice too.
upvoted 0 times
...
Annamae
10 months ago
I think Wireshark is definitely one of the tools we should use since it captures packets in real-time and has a user-friendly interface.
upvoted 0 times
...
Ilene
10 months ago
Wireshark and tcpdump are the clear winners here. They're both powerful packet capture tools that will give the investigator the data they need. Just gotta make sure to run them properly.
upvoted 0 times
...
Bernadine
11 months ago
I'm a bit unsure about this one. I know Wireshark is a network sniffer, but I'm not sure about tcpdump. Guess I'll have to review my notes on network forensics tools.
upvoted 0 times
...
Kimbery
11 months ago
Piece of cake! Wireshark and tcpdump are the go-to tools for packet capturing. Just make sure to save the output to a file for the investigator.
upvoted 0 times
...
Janna
11 months ago
Hmm, I'm not too familiar with network tools like these. Wireshark and tcpdump sound like the right options, but I'll have to double-check the details.
upvoted 0 times
...
Refugia
11 months ago
This one's easy, I've used Wireshark and tcpdump before for network analysis. Gotta capture those packets!
upvoted 0 times
...
Chan
11 months ago
I agree with Kristofer, Wireshark is a great tool for capturing network traffic.
upvoted 0 times
...
Kristofer
11 months ago
I think we should use Wireshark to capture incoming IP packets.
upvoted 0 times
...

Save Cancel