ETExamTower
Q18Security MonitoringMultiple answers

What are the two characteristics of full packet captures? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
E
50% (9)
B
33% (6)
C
17% (3)
A
0% (0)
D
0% (0)
Discussion · 21
12
It's BE
4
"C" is correct. IP Reassembly IP Reassembly is a feature in Wireshark and TShark to automatically reassemble all fragmented IP Datagrams into a full IP packet before calling the higher layer dissector. Ref: https://wiki.wireshark.org/IP_Reassembly This feature will need a lot of extra memory to be consumed by wireshark in order to store the reassembly buffers and is disabled by default. "E" is correct. By the book: Packet captures provide a full historical record of a network transaction or an attack. It is important to recognize that no other data source offers this level of detail. There are many studies of cases of using Wireshark to troubleshoot the cause of security and performance issues. So, "B" would also be right. But the other options are more direct.
C, E 3
Selected Answer: CE Let's begin with the word itself. "Characterstics" Characteristics - a feature or quality belonging typically to a person, place, or thing and serving to identify it. >>Characteristics<< - Reassembling fragmented traffic from raw data. - Providing a historical record of a Network Transaction. >>Use cases or Diagnostics<< - Identifying network loops and Collision Domains. - Troubleshooting the cause of security and performance issues. - Detecting common hardware faults and identifying faulty assets.
B, E 3
Selected Answer: BE Option C is not necessarily wrong, but it is not one of the two characteristics of full packet captures the question is asking for. Reassembling fragmented traffic from raw data is a capability of full packet capture and can be useful for analyzing and understanding network traffic. However, the question is specifically asking for the two main characteristics of full packet capture.
2
correct it can reassemble the data that is in the same session
C, E 2
Selected Answer: CE Clearly, because we are here for cybersecurity, the other answers can be for net engineers.
B, E 2
Selected Answer: BE B and E seem like the better answer
1
why not C ? P Reassembly is a feature in Wireshark and TShark to automatically reassemble all fragmented IP Datagrams into a full IP packet before ... This feature will need a lot of extra memory to be consumed by wireshark in order to store the ... You have captured packets with a SnapLen less than the MTU of the ...
1
P Reassembly is a feature in Wireshark and TShark to automatically reassemble all fragmented IP Datagrams into a full IP packet before ... This feature will need a lot of extra memory to be consumed by wireshark in order to store the ... You have captured packets with a SnapLen less than the MTU of the ... I feel C is a better choice than B
1
C and E seem like the correct answers. I don't exclude B because troubleshooting often uses Wireshark. ops .. but this is the third.
1
It is BE. The question is about full packet capture and not about packet analyzers. "Full Packet Capture (FPC) provides a network defender an after-the-fact investigative capability that other security tools cannot provide. Uses include capturing malware samples, network exploits and determining if data exfiltration has occurred. Full packet captures are a valuable troubleshooting tool for operations and security teams alike." https://sansorg.egnyte.com/dl/v6XafdW96e
C, E 1
Selected Answer: CE C & E seem to be the correct answer.
B, E 1
Selected Answer: BE BE is the right answer.
1
that's not the right choice. If you can, please delete the comment.
1
So C E is correct?
1
Yes, that makes sense. We should be thinking like Security / SOC Engineers and not like a Network Engineer.
1
The two characteristics of full packet captures are: B. Troubleshooting the cause of security and performance issues. E. Providing a historical record of a network transaction. Options A, C, and D are not characteristics of full packet captures
B, E 1
Selected Answer: BE I agree it is BE
B, E 1
Selected Answer: BE B and E for me
1
BD Not only are network protocol analyzers used for security analysis. They are also very useful for network troubleshooting, software and protocol development, and education. For instance, in security forensics, a security analyst may try to reconstruct an incident from relevant packet captures.
1
BE is the correct answer. About B: Packet capture lets teams deal with complex network issues with ease and efficiency. - https://www.solarwinds.com/resources/it-glossary/pcap