Network forensics Flashcards

Know all basic network functions

1
Q

what is wireshark

A

wireshark is a GUI that is used to determine network packets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is wireshark used for solving?

A

troubleshooting network issues
Network security issues
Debugging protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a capture filter

A

Capture filter is a filter that captures traffic that specifically matches that capture filter rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the benefits of a capture filter

A

prevents packet loss
saves disk space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a display filter?

A

to tweak appearance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does this filter mean “ ip.addr == 10.0.0.1

A

Sources/ destination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does this filter mean 10.0.0.1 and 10.0.0.2

A

Communication between packets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what does this filter mean http or dns

A

displays filter for all http or dns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what does this filter mean tcp.port.4000

A

find the specific tcp port 4000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what does this filter mean tcp.flags.reset

A

reset all tcp flags

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what does this filter mean http.request

A

display all http requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what does this filter mean tcp contains reviews

A

find all tcp packets that contain the word review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what does this filter mean ! (arp, icmp and dns)

A

don’t find either of these three protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly