WorksheetsIT 412- System Administration & Maintenance
Total questions: 50
Worksheet time: 33mins
Which of the following best describes a "packet"?
A segment of network data transmission
A screenshot of network traffic
A secure password file
An image file used in networking
The top 3 layers are typically implemented in software within the Operating System.
Application, Presentation, Session
Presentation, Session, Physical
Session, Physical, Transport
Network Layer, Physical, Transport
It enables us to access web applications.
HTTP
FTP
SNMP
Network Layer
It allows users to transfer files.
HTTP
FTP
SNMP
Network Layer
It protocol to read and update network device configurations.
HTTP
FTP
SNMP
Network Layer
It is used for many applications, ensuring stability, control of how much data can be sent.
TCP
UDP
SNMP
QUIC
It is used for lightweight and quick protocol use for many services..
TCP
UDP
SNMP
QUIC
It is a protocol designed for faster connections and goes hand-in-hand with the version 2 of the HTTP protocol.
TCP
UDP
SNMP
QUIC
It is used everyday when accessing the Internet. Comes in two versions, IP version 4 and 6.
IP
ICMP
SNMP
QUIC
It is used by network devices and network operators, to diagnose network
IP
ICMP
SNMP
QUIC
It allows encrypted and secure connections between two network devices.
IP
ICMP
IPSec
QUIC
It is essential protocol used by most operating systems when connecting to networks using a physical cable.
IP
Ethernet
IPSec
QUIC
It is for accessing networks via radio signals. It uses a family of protocols called IEEE 802.11.xx.
Wi-Fi
Ethernet
IPSec
NDP
What is DHCP stand for?
(a)
It says computer systems often needs to talk to other systems; this is done by putting them on the same network. Several different technologies are in place to enable computers to talk over different kinds of networks. In this section we will go deeper into the protocols which are used in most networks. TRUE/ FALSE
TRUE
FALSE
is an open-source library for packet capture and network analysis for the Win32 platforms. Most networking applications access the network through widely used operating system primitives such as sockets
(a)
is the Windows version of the libpcap library; it includes a driver to support capturing packets.
(a)
It is considered as a central architectural element to any network.
(a)
The packet list pane, located at the top of the window, shows all packets found in the active capture file. Each packet has its own row and corresponding number assigned to it, along with each of these data points:
(a)
Is the verb we are using to access the application. Explained in detail in the section HTTP Verbs. We also see the path and query parameters and HTTP version
(a)
What is Wireshark primarily used for?
Image editing
Network packet analysis
File encryption
Database management
Which of the following file formats can Wireshark export packet captures to?
.xt
.pcap
.MP4
.doc
Which filter would you use to display only HTTP traffic?
ip.src == HTTP
port 443
http
udp
In which menu can you find "Capture Filters"?
Edit
File
Analyze
Capture
What is the default capture file format in Wireshark?
.txt
.cap
.pcapng
.csv
What is the purpose of the “Statistics” menu in Wireshark?
To capture packets
To view detailed protocol information
To modify packets
To apply color filters
Which type of traffic would be shown by the filter tcp.port == 80?
HTTPS
FTP
HTTP
SSH
Which of the following can Wireshark NOT analyze?
Wireless packets
Encrypted payloads without keys
TCP streams
UDP traffic
What color does Wireshark typically use for TCP traffic in its default color scheme?
Blue
Green
Red
Yellow
If you want to filter traffic from a specific IP address, what filter syntax would you use?
How can you prevent capturing packets that are not relevant?
Apply Display Filters
Use Capture Filters
Adjust Graph Settings
Use Analyze Filters
What does the “Protocol Hierarchy” statistic in Wireshark show?
A list of all packet sizes
A breakdown of protocols and their usage in the capture
The number of hosts on the network
The location of packet errors
What does the “Decode As” option allow you to do?
Change file formats
Specify how Wireshark interprets certain packets
Edit packet headers
Remove duplicate packets
What does Wireshark's user-friendly interface help with?
Building houses
Cooking
Analyzing data
Playing sports
What is one of the tools in Wireshark?
Musical instruments
Art supplies
Cooking tools
Packet filters
What is the name of the tab to be able to graph
(a)
What does Wireshark help with in security analysis?
Detecting security vulnerabilities
Making food
Playing games
Drawing
What type of traffic can Wireshark analyze?
Traffic in a game
Traffic on the road
Traffic in a movie
Network traffic
What is a practical example of using Wireshark?
Analyzing HTTPS communication
Cooking dinner
Playing soccer
Reading a book
What does Wireshark allow users to apply?
Filters to draw
Filters to play games
Filters to cook food
Filters to capture specific packets
What is one of the advantages of Wireshark?
It does not work on computers
It is only for experts
Comprehensive analysis of network traffic
It is very expensive
What is NMAP?
Footprinting tool
Network Topology Map
Scanner for malware
none of the above
What is a PCAP file?
A file created from a packet capture
A report from Wireshark
A report of all malware on the system
none of the above
After plaintext messages have been encrypted, the encrypted text is known as which of the following?
algorithm
decipher
cleartext
ciphertext
Wireshark is an example of what type of utility?
Port scanner
Content filter
Packet sniffer
Vulnerability scanner
Which of the following terms best describe a firewall type that can react to network traffic and create or modify configuration rules to adapt?
application layer firewall
dynamic packet filtering firewall
proxy firewall
content filter
Wireshark can capture packets in real-time and save them to a file for later analysis. TRUE/ FALSE
TRUE
FALSE
Wireshark can't identify traffic coming into a network, its frequency, and its latency. TRUE/ FALSE
TRUE
FALSE
Troubleshooting networks: Wireshark can help cybersecurity professionals troubleshoot networks by tracing connections and gathering an overview of suspected transactions. TRUE/ FALSE
TRUE
FALSE
Identifying bursts: Wireshark can help identify bursts that are prevalent in network traffic. TRUE/ FALSE
TRUE
FALSE
