Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC GCED Exam - Topic 3 Question 75 Discussion

Actual exam question for GIAC's GCED exam
Question #: 75
Topic #: 3
[All GCED Questions]

What feature of Wireshark allows the analysis of one HTTP conversation?

Show Suggested Answer Hide Answer
Suggested Answer: B

Follow TCP Stream is a feature of Wireshark that allows the analysis of a single TCP conversation between two hosts over multiple packets. Filtering packets using tcp in the filter box will return all TCP packets, not grouping by a single TCP conversation. HTTP is TCP not UDP, so you cannot follow a HTTP stream over UDP.


Contribute your Thoughts:

0/2000 characters
Natalie
4 days ago
I might be confusing it, but I feel like "Follow UDP Stream" is for different protocols. I don't think it applies to HTTP.
upvoted 0 times
...
Andra
9 days ago
I remember practicing with Wireshark and using the "Follow TCP Stream" option for analyzing conversations. It seems like the best choice here.
upvoted 0 times
...
Pamella
14 days ago
I think it's B) Follow TCP Stream, since HTTP runs over TCP, right? But I'm not completely sure.
upvoted 0 times
...

Save Cancel