Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 7 Question 68 Discussion

Refer to the exhibit.A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the Wireshark traffic logs?
D) tcp.window_size ==0
A) http.request.un matches
B) tls.handshake.type ==1
C) tcp.port eq 25

Cisco 300-215 Exam - Topic 7 Question 68 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 68
Topic #: 7
[All 300-215 Questions]

Refer to the exhibit.

A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the Wireshark traffic logs?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Sarah
9 months ago
D seems irrelevant, window size doesn't help with HTTP requests.
upvoted 0 times
...
Sena
10 months ago
C is definitely not it, that's for email traffic.
upvoted 0 times
...
Chaya
10 months ago
Wait, could it actually be B? TLS is involved too, right?
upvoted 0 times
...
Agustin
10 months ago
Totally agree, A makes the most sense here!
upvoted 0 times
...
Nickole
10 months ago
I think the right filter is A, it targets HTTP requests.
upvoted 0 times
...
Reuben
10 months ago
I don’t think "tcp.port eq 25" is right since that’s usually for SMTP, not HTTP. It’s tricky remembering all these filters!
upvoted 0 times
...
Barbra
11 months ago
I’m leaning towards option A as well, but I recall a question where we had to differentiate between HTTP and other protocols.
upvoted 0 times
...
Gearldine
11 months ago
I remember practicing with Wireshark filters, and I feel like "tls.handshake.type == 1" is more related to secure connections rather than HTTP requests.
upvoted 0 times
...
Willodean
11 months ago
I think the filter for HTTP requests might be the one that includes "http.request.un matches," but I'm not entirely sure if that's the exact syntax.
upvoted 0 times
...
Aleta
11 months ago
Aha, I think I've got it! The question is asking for the filter the engineer used to sort the traffic logs, so I'm guessing the answer is related to filtering HTTP requests.
upvoted 0 times
...
Novella
11 months ago
I'm a bit confused by the options here. None of them seem to directly match the description in the question. I'll need to review my Wireshark knowledge to figure this out.
upvoted 0 times
...
Kiley
11 months ago
Okay, let me see... the question mentions an HTTP request that caused a banking Trojan to download, so I'm guessing I need to look for a filter related to HTTP traffic.
upvoted 0 times
...
Kate
11 months ago
Hmm, this looks like it's testing my knowledge of Wireshark filters. I'll need to think carefully about the clues in the question to determine the right filter.
upvoted 0 times
...
Myong
11 months ago
Hmm, I'm not totally sure about this one. I know the RIB has a bunch of different fields, but I'm not confident which one specifically handles the egress direction. I'll have to think this through carefully.
upvoted 0 times
...
Arleen
11 months ago
Hmm, this is a tricky one. I think the key is to make sure I have 100% test coverage on the Apex trigger, not just the helper class. I'll need to create some additional test methods to fully exercise the trigger.
upvoted 0 times
...
Sabra
11 months ago
This seems like a straightforward question about the advanced search capabilities of the Physical Analyzer tool. I'll carefully read through the options and think about which one best matches the description provided.
upvoted 0 times
...
Marti
1 year ago
I have to say, these Wireshark filters are starting to sound like Klingon to me. Why can't they just call it 'Find the Bad Guy' filter?
upvoted 0 times
Page
1 year ago
User 3: It's all about finding the needle in the haystack.
upvoted 0 times
...
Irving
1 year ago
User 2: I agree, it feels like learning a new language.
upvoted 0 times
...
Fredric
1 year ago
User 1: I know right, these filters can be so confusing.
upvoted 0 times
...
...
Amie
1 year ago
D) tcp.window_size ==0? What kind of weird filter is that? I'm pretty sure the answer has to be one of the HTTP-related options. Maybe Jolanda is onto something with that http.request.un matches filter.
upvoted 0 times
Jettie
1 year ago
I agree, let's go with that option for sorting the Wireshark traffic logs.
upvoted 0 times
...
Aleisha
1 year ago
Yeah, that filter seems more relevant to finding the HTTP request for the Ursnif banking Trojan.
upvoted 0 times
...
Mammie
1 year ago
I think Jolanda might be right with the http.request.un matches filter.
upvoted 0 times
...
...
Albina
1 year ago
Hmm, I was leaning towards C) tcp.port eq 25, since that could detect the SMTP traffic associated with the malware. But I guess the HTTP request is the more direct way to identify the initial download.
upvoted 0 times
Herman
1 year ago
User3: I agree, it's the most direct way to identify the Ursnif banking Trojan binary download.
upvoted 0 times
...
Haley
1 year ago
User2: Yeah, that filter would specifically target the HTTP request we are looking for.
upvoted 0 times
...
Kenneth
1 year ago
User1: I think the correct filter is A) http.request.un matches
upvoted 0 times
...
...
Alisha
1 year ago
I was thinking B) tls.handshake.type ==1 might be the right answer, since the Ursnif malware is likely using encrypted communication. But you make a good point, A) is probably the best choice here.
upvoted 0 times
...
Jolanda
1 year ago
I'm pretty sure the answer is A) http.request.un matches. The question is specifically asking about the HTTP request that triggered the Ursnif download, so that filter seems like the most relevant one.
upvoted 0 times
...
Truman
1 year ago
But the question specifically mentions analyzing the HTTP request, so A) seems more relevant.
upvoted 0 times
...
Berry
1 year ago
I disagree, I believe the correct answer is B) tls.handshake.type ==1.
upvoted 0 times
...
Truman
1 year ago
I think the answer is A) http.request.un matches.
upvoted 0 times
...
Davida
1 year ago
But the question specifically mentions analyzing the HTTP request, so A) seems more relevant.
upvoted 0 times
...
Shanice
1 year ago
I disagree, I believe the correct answer is B) tls.handshake.type ==1.
upvoted 0 times
...
Davida
1 year ago
I think the answer is A) http.request.un matches.
upvoted 0 times
...

Save Cancel