Module H2: Common Network Traffic Flashcards
What type of data does an Ethernet frame hold?
Abstracted Data
Logical Data
Imported Data
Encapsulated Data
Encapsulated Data
What IEEE standard defines Ethernet connections?
802.3
How many bytes are in Ethernet frame preamble?
7
How many bits are in an Ethernet frame preamble?
56
Which comes first in an Ethernet frame, the destination or source address?
destination
Which part of the Ethernet frame enables synchronization?
preamble
What is contained in the destination address field?
mac address
What is the maximum amount of bytes that the data field can have?
1500
If the minimum length of the data field is not met, what is the process called of added zero byte values to make the data field meet the requirements?
- Padding
- Stretching
- Buffing
- Zeroing
Padding
If you wanted to create a filter in wireshark that only showed packets from a specific mac address what would that filter look like?
eth.src ==
What do the first 3 bytes of the destination or source mac address show us?
- Frame Source
- Destination Address
- OUI / organizationally unique identifier
- Hop Count
OUI / organizationally unique identifier
What are the three types of network traffic communications?
- NCP, NBP, RGP
- Unicast, broadcast, multicast
- Comcast, Dreamcast, OutKast
- 2.4 GHz, 5 GHz, 11 GHz
Unicast, broadcast, multicast
What is a command line tool for packet capture on most unix systems?
tcpdump
What type of scan is used to see if ports are open or active on a remote device?
port
What part of the Ethernet frame is always set to 0xAB
Start Frame Delimiter
What is the total size of an IPv4 datagram (in bytes)?
65,535
If mapping for a local destination host is not found in the source host ARP cache, what does the source host do to send the request?
broadcast
This kind of data transmission allows data to be transmitted in both directions on a signal carrier at the same time.
For instance, one workstation can be sending data on the line while another workstation is receiving data.
full duplex
On an Ethernet network, this is the unit of data that is transmitted between network points.
It has explicit minimum and maximum lengths and a set of required pieces of information that must appear within it.
frame
What happens if two devices on the same Ethernet network determine the network is free, but attempt to transmit data at exactly the same time.
collision
What is the BPF to filter for the Ethertype in the Ethernet header?
ether[12:2]
What is Ethertype 0x0800?
- IPv4
- ARP
- VLAN Tagging
- IPv6
IPv4
What is byte 0 on the Ethernet header?
Destination MAC Address
What is the byte offset of the “Ethertype” field in the Ethernet header?
12
What is the Ethertype for IPv6?
0x86DD
What is the Wireshark Filter to filter source MAC address of 00:8b:3c:54:f8:00
eth.src == 00:8b:3c:54:f8:00
What is the Wireshark Filter to filter source MAC address of 00:8b:3c:54:f8:00?
eth.src == 00:8b:3c:54:f8:00
What is the Ethertype for VLAN Tagging?
0x8100
Which TCPDump switch option is used to show the MAC addresses associated with a packet?
-e