wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Wireshark Assessment

Total questions: 60

Worksheet time: 43mins

Name
Class
Date
1.

Wireshark was originally known as (a)   .

2.

Wireshark supports multiple file formats including CAP and (a)   .

3.

Wireshark can be used to analyze traffic in (a)   time.

4.

The two libraries used for packet capture on Windows are WinPcap and (a)   .

5.

Wireshark can be downloaded for free from the (a)   website.

6.

Wireshark includes tools to decrypt protocols such as WEP and (a)   .

7.

Npcap is based on the (a)   library.

8.

WinPcap is designed for (a)   platforms.

9.

Wireshark is available for macOS, Windows, Linux, and other (a)   platforms.

10.

The top pane of the Wireshark interface is called the (a)   pane.

11.

To begin capturing data, you must select a network from the Wireshark (a)   screen.

12.

Display filters are applied (a)   packet capture begins.

13.

The line graph next to network connections indicates (a)   traffic.

14.

Packets with the same conversation are grouped by the field labeled (a)   .

15.

CIDR stands for Classless Inter-Domain (a)   .

16.

What was the original name of Wireshark?

a)

NetCapture

b)

PacketSniff

c)

Ethereal

d)

NetScan

17.

Which file format is supported by Wireshark?

a)

DOC

b)

ERF

c)

XLS

d)

PDF

18.

Wireshark was originally called Ethereal. (True/False)

a)

True

b)

False

19.

Npcap is only compatible with macOS. (True/False)

a)

True

b)

False

20.

Which operating systems does Wireshark support?

a)

Only Windows

b)

Windows, macOS, Linux, and Unix-like systems

c)

Only macOS

d)

Only Linux

21.

What type of software is Wireshark?

a)

Proprietary software

b)

Open-source software

c)

Paid software

d)

Game software

22.

What does Wireshark capture?

a)

Text documents

b)

Videos

c)

Images

d)

Network packets

23.

What can Wireshark decode?

a)

Network protocols

b)

Music files

c)

Books

d)

Video games

24.

What is a disadvantage of using Wireshark?

a)

It is too easy to use

b)

It does not work on computers

c)

Large data sets can be overwhelming

d)

It is only for experts

25.

What does Wireshark's user-friendly interface help with?

a)

Building houses

b)

Cooking

c)

Analyzing data

d)

Playing sports

26.

What is one of the tools in Wireshark?

a)

Musical instruments

b)

Art supplies

c)

Cooking tools

d)

Packet filters

27.

What is the name of the tab to be able to graph

(a)  

28.

What does Wireshark help with in security analysis?

a)

Detecting security vulnerabilities

b)

Making food

c)

Playing games

d)

Drawing

29.

What type of traffic can Wireshark analyze?

a)

Traffic in a game

b)

Traffic on the road

c)

Traffic in a movie

d)

Network traffic

30.

What is a practical example of using Wireshark?

a)

Analyzing HTTPS communication

b)

Cooking dinner

c)

Playing soccer

d)

Reading a book

31.

What does Wireshark allow users to apply?

a)

Filters to draw

b)

Filters to play games

c)

Filters to cook food

d)

Filters to capture specific packets

32.

What is one of the advantages of Wireshark?

a)

It does not work on computers

b)

It is only for experts

c)

Comprehensive analysis of network traffic

d)

It is very expensive

33.

What does ICMP stand for in networking?

a)

Internal Communication Management Process

b)

Internet Connection Monitoring Program

c)

Interconnected Computer Memory Protocol

d)

Internet Control Message Protocol

34.

Which of the following best describes a "packet"?

a)

A segment of network data transmission

b)

A screenshot of network traffic

c)

A secure password file

d)

An image file used in networking

35.

It allows users to transfer files.

a)

HTTP

b)

FTP

c)

SNMP 

d)

Network Layer

36.

It is used by network devices and network operators, to diagnose network

a)

IP 

b)

ICMP

c)

SNMP 

d)

QUIC 

37.
How do you filter for HTTP traffic in Wireshark?
a)
Use the filter `tcp.port == 53`
b)
Use the filter `ip.addr == 192.168.1.1`
c)
Use the filter `dns`
d)
Use the filter `http`
38.
What is a common sign of eavesdropping or network manipulation in HTTP traffic?
a)
High volume of SYN packets
b)
Excessive HTTP requests to one server
c)
Unexpected data in HTTP packets, such as altered content
d)
Slow DNS resolution times
39.
How can you detect DNS anomalies or spoofing in Wireshark?
a)
By focusing on SYN packets
b)
By monitoring only ICMP traffic
c)
By identifying multiple DNS responses from different sources for the same query
d)
By looking at UDP traffic only
40.
What does the "Statistics" menu in Wireshark help you analyze?
a)
Raw packet bytes
b)
Network traffic patterns, protocols, and endpoints
c)
Only DNS traffic
d)
Packet header details
41.
What does the "Display Filter" in Wireshark do?
a)
To view only HTTP traffic
b)
To summarize packet data
c)
To isolate specific packets during a capture
d)
To prevent packets from being captured
42.
What is a common indicator of a port scan in Wireshark?
a)
Slow packet responses
b)
High UDP packet counts
c)
Repeated SYN packets from one source to multiple destinations
d)
Unusual DNS traffic
43.
How do you start a packet capture in Wireshark?
a)
Click "Statistics" > "Start Capture"
b)
Click "File" > "Open"
c)
Click "Edit" > "Preferences"
d)
Click "Capture" > "Start"
44.

What is a dissector in Wireshark?

a)

A protocol message handler

b)

A tool for packet analysis

c)

A network security feature

d)

A data visualization tool

45.

Which of the following is NOT a feature of Wireshark dissectors?

a)

Display filters

b)

Send Packet Data

c)

Protocol element types

d)

Payload handling

46.

What is the name of the interface on the top section pane used to view captured data in Wireshark ?

(a)  

47.

What is the name of the interface on the left section pane used to view captured data in Wireshark ?

(a)  

48.

What is the name of the interface on the right section pane used to view captured data in Wireshark ?

(a)  

49.

The timestamp of when the packet was captured is displayed in this column. The default format is the number of seconds or partial seconds since this specific capture file was first created.

(a)  

50.

This column contains the address (IP or other) where the packet originated.

(a)  

51.

This column contains the address that the packet is being sent to.

(a)  

52.

The packet's protocol name, such as TCP, can be found in this column.

(a)  

53.

The packet length, in bytes, is displayed in this column.

(a)  

54.

Additional details about the packet are presented here. The contents of this column can vary greatly depending on packet contents.

(a)  

55.

What is the primary purpose of using Wireshark?

a)

To create websites

b)

To play online games

c)

To edit videos

d)

To analyze network traffic

56.

Which protocol is commonly analyzed using Wireshark?

a)

HTTP

b)

SMTP

c)

FTP

d)

All of the above

57.

What feature does Wireshark provide for visualizing network traffic?

a)

Audio playback

b)

Text documents

c)

3D animations

d)

Graphs and charts

58.

How does Wireshark capture network packets?

a)

By intercepting radio signals

b)

By analyzing server logs

c)

By encrypting data streams

d)

By passively listening to network communication

59.

How can Wireshark be used to identify and troubleshoot slow network performance?

a)

By uninstalling Wireshark and reinstalling it

b)

By analyzing DNS requests

c)

By ignoring network performance issues

d)

By examining TCP retransmissions and high response times

60.

Which display filter is used to show only HTTP traffic in Wireshark?

a)

ip.addr == 192.168.1.1

b)

protocol == HTTP

c)

dns.query

d)

tcp.port == 80