[Aug-2023] Protocol Analysis WCNA Official Cert Guide PDF
Exam WCNA: Wireshark Certified Network Analyst Practice Exam - Actual4test
NEW QUESTION # 48
Columns can be reordered by dragging them into their new positions directly in the Packet List pane.
- A. False
- B. True
Answer: B
NEW QUESTION # 49
Some ICMP packets include portions of the original packet that triggered the ICMP response.
- A. False
- B. True
Answer: B
NEW QUESTION # 50
Null scans use legal TCP packet formats, but listen for illegally-formed TCP response packets.
- A. False
- B. True
Answer: A
NEW QUESTION # 51
A TCP Acknowledgment Numberfield that is never incremented by a host after the TCP handshake indicates that no data is being received by that host.
- A. False
- B. True
Answer: B
NEW QUESTION # 52 
This packet shows the expanded TCP flags area. The display filter tcp.fiags.syn==1 && tcp.flags.ack==1 and the display filter tcp.fiags=0xi2 provide identicalfiltering results.
- A. False
- B. True
Answer: B
NEW QUESTION # 53
By default, Wireshark will only dissect port 443 traffic as SSL/TLS traffic. If you are using another port for SSL/TLS communications, you must add that port number in the HTTP preferences setting for SSL/TLS ports.
- A. False
- B. True
Answer: B
NEW QUESTION # 54
Applications may override the default port value defined in the TCP/IP stack services file.
- A. False
- B. True
Answer: B
NEW QUESTION # 55
Whichstatement about ICMP is true?
- A. All ICMP packets are the same length.
- B. ICMP packets cannot cross a router.
- C. ICMP packets do not contain a UDP or TCP header.
- D. Port filtering can block ICMP traffic.
Answer: C
NEW QUESTION # 56
You are analyzing network traffic, but you only see ARP queries - you do not see any ARP responses. What could cause this situation?
- A. You have applied an ip filter to the traffic.
- B. You are connected to a switch port that is not spanned.
- C. You are filtering on IP addresses for another network.
- D. Wireshark is not running in monitor mode.
Answer: B
NEW QUESTION # 57
Which transport is used for multicast and broadcast traffic?
- A. TCP
- B. UDP
- C. ARP
- D. ICMP
Answer: B
NEW QUESTION # 58 
This image shows frame 2781which is a Window Update packet. This packet indicates that 10.0.52.164's TCP Window Size field value has increased since the last packet sent by that host.
- A. False
- B. True
Answer: B
NEW QUESTION # 59
Which term defines an alias name used in DNS responses?
- A. ALIAS
- B. PTR
- C. CNAME
- D. HOST
Answer: C
NEW QUESTION # 60
When you disable the UDP protocol decoding process, applications that use UDP (such as DHCP and DNS) will not bedecoded.
- A. False
- B. True
Answer: B
NEW QUESTION # 61
Wireshark can import CSV (comma separated value) format files for further analysis.
- A. False
- B. True
Answer: B
NEW QUESTION # 62
The capture filter syntax for all FTPcommand and data channel traffic is tcp port 21.
- A. False
- B. True
Answer: A
NEW QUESTION # 63
The gratuitous ARP process is not required if a host is configured with a static IP address.
- A. False
- B. True
Answer: A
NEW QUESTION # 64
Both the capture and display filter syntax for ARP requests and replies is arp.
- A. False
- B. True
Answer: B
NEW QUESTION # 65
DHCP is based on BOOTP.
- A. False
- B. True
Answer: B
NEW QUESTION # 66 
Which statement about the Capture Options window shown is correct?
- A. Wireshark will scroll to displaythe most recent packet captured.
- B. Wireshark will attempt to resolve OUI values for all MAC addresses.
- C. Wireshark will resolve IP addresses to host names.
- D. Wireshark will automatically stop capturing packets after two files have been saved.
Answer: A
NEW QUESTION # 67
......
Free WCNA Exam Dumps to Improve Exam Score: https://www.actual4test.com/WCNA_examcollection.html
2023 Realistic WCNA Dumps Exam Tips Test Pdf Exam Materials: https://drive.google.com/open?id=16w9ybT8KH4C2TWQ-Slc6HpHFxx0R65KC