ETExamTower
Q19Network Intrusion Analysis

Refer to the exhibit. Which application protocol is contained in this PCAP file?

Question exhibit
← → navigate · a answer
Community votes
D
71% (5)
C
29% (2)
A
0% (0)
B
0% (0)
Discussion · 26
27
Correct answer should be "D". TCP is not an application layer protocol. Http is, and the used port is 443 (https).
6
The correct is TLS over HTTP I believe "C" is correct.
C 6
Selected Answer: C A. SSH - port 22 B. TCP - not application protocol (it is a transport protocol) *C. TLS - port 443 D. HTTP - port 80 The aim of the question is to test whether you know the TCP ports and ISO/OSI layers.
5
SSH = port 22 (standard port number) TCP = a transport protocol (They ask for a application protocol) so this one is ruled out. TLS = depending what its used for can be other ports, but in this case i assume they talk about port 443 HTTP = 80 (standard port number) Now in the packet capture frame 24 the Dst Port shows 443. I believe TLS is the correct answer here.
4
Vote for C because the next question 112 says that TLS is an application level protocol
4
Whoever wrote this question has confused everyone by asking which "application layer" protocol is in use, and there is only one application layer protocol in this list (HTTP). The actual protocol shown by Wireshark is SSL/TLS but that is a presentation layer protocol. So the question is a mess and needs to be cleared up.
3
It's a very tricky or wrong question Partially I agree with you, but the correct answer actually should be "B", because wireshark automatically identifies and recognises TLS as a protocol (Make sure in the next #112 question - TLSv1.2) and also HTTP. On the one hand, in this captured packet there isn't a TLS header/layer. Although the port is TCP443, that doesn't mean it is HTTPS traffic! It's only traffic that uses TCP443: for an extreme idiot example, this traffic could be telnet traffic with a modified port number. On the other hand, the HTTP answer is also wrong: first, wireshark recognises HTTP too; second, in this case the bulk data/body is shown in the captured packet as "Hyperttext Transfer Protocol" not as simple "Data [205 byte]" I know there is a "www" data in the body, but that doesn't mean it is a real HTTP packet. And I know TCP isn't an application protocol, so maybe the question is also wrong. But I think the key here is the port/TCP, not an upper layer protocol.
3
Http is port 80 but TLS is 443
3
Answer should be C
2
TLS is an Application Protocol, So answer is TLS
2
Wikipedia: TLS belongs to the Application layer in terms of the TCP/IP model.
D 2
Selected Answer: D The answer is D. Because if you look carefully, you will see that the coded part below has the text "http/1.1."
C 2
Selected Answer: C I Think it is TLS
1
or maybe the mistake is in the question. It should be: "Which protocol.." In that case, TCP is the correct answer
1
So it's TLS over HTTP
1
A TLS session runs over a TCP connection. TLS is in charge of the encryption and authentication of the SDUs exchanged by the application layer protocol while TCP gives the reliable delivery of this encrypted and authenticated bytestream. TLS is used by many different application layer protocols. The most common ones are HTTP (HTTP over TLS is called HTTPS 443). TCP is layer 4 protocol not layer 7.
1
Correct answer should be D-> HTTP. The capture in the PCAP indicates : "www.linuxnint.....http1/1...". Besides that it is inside Data ( 205 bytes) . Imagine why is the complete capture showing all screen?
1
Correct answer is TLS (not V1.3). With TLS, the first part of the URL (https://www.example.com/) is still visible as it builds the connection.
1
Answer C: The captured frame contains TLS (Transport Layer Security) protocol. The frame in the PCAP capture shows that the packet is using Transmission Control Protocol (TCP) as the transport layer protocol. However, the data payload in the packet is encrypted and cannot be determined without more analysis. The use of port 443 as the destination port in the TCP header suggests that this is a secure web session using HTTPS. HTTPS uses Transport Layer Security (TLS) to provide encryption for the communication. Therefore, the correct answer is C - TLS. HTTP is not the correct answer because HTTP does not provide encryption for the communication. It is possible that the encrypted data in the packet is related to HTTP traffic, but that cannot be determined from the given information. SSH is not the correct answer because SSH uses a different port number (usually port 22) and a different protocol for secure shell access.
1
TLS (Transport Layer Security) is a protocol that is usually implemented at the transport layer of the OSI model. While it is not strictly an application-layer protocol like HTTP or SMTP, it is often used to secure application-layer protocols such as HTTP, SMTP, and FTP. So, depending on the context in which the term "application protocol" is used, TLS may be seen as an application protocol or a lower-level protocol. In the context of the given question, where the options were SSH, TCP, TLS, and HTTP, TLS is the most suitable answer.
D 1
Selected Answer: D The destination port number 443 shows that the application protocol in this PCAP file is HTTPS (HTTP over TLS/SSL). Port 443 is the well-known port for secure HTTP communication, better known as HTTPS. In the PCAP file, you can see the TCP SYN and SYN-ACK packets exchanged between the source and destination, followed by TLS handshake packets (PSH, ACK) showing the setup of a secure connection. The data in the PCAP file shows the encrypted TLS/SSL payload. Therefore, the application protocol in this PCAP file is HTTPS.
1
I'd agree with this.
1
D- HTTP is the correct answer. When HTTP is used over TLS (HTTPS) on port 443, the application protocol is still HTTP. But it is secured with Transport Layer Security (TLS) to encrypt the communication between the client and the server. The mix of HTTP and TLS gives HTTPS, which is the secure version of HTTP. The application layer protocol stays HTTP, but it runs over a secure TLS-encrypted connection, providing confidentiality and integrity for the data exchanged between client and server.
1
But TLS is not application protocol either mate, question is just dumb
D 1
Selected Answer: D Il traffico è in chiaro, tls è crifrato quindi la risposta giusta è http
D 1
Selected Answer: D The correct answer is D. Application Layer Protocol: HTTPS is just HTTP running over an encrypted transport layer (TLS). Since the question specifically asks for the application protocol, HTTP is the correct choice.