Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

View a video about Wireshark on Lynda.com 1. What are the five commonly accessed

ID: 3572722 • Letter: V

Question

View a video about Wireshark on Lynda.com

1. What are the five commonly accessed menu choices?

2. Open the file “A TCP-Example.pcapng” as in the video, and follow the instructions given to edit this file. In Wireshark Preferences, which box does the author suggest unchecking (or keeping unchecking)? Why?

3. Continuation of 2): Which box does the author suggest checking (or keeping checked)? Why?

4. Under which menu choice is the Time Display Format?

5. How would you determine the manufacturer of a NIC?

6. Which View option shouldn’t be activated? Why?

7. Where is the Summary option and what information does it give you?

8. How do you set up a capture filter to capture DNS packets?

9. Under what circumstances should you consider not using a capture filter? Why?

10. What is the Expression Builder used for?

11. How do you choose only the acknowledgement flag set in TCP?

12. Try Challenge: Filtering Data that is Displayed. Take a screenshot of your trial.

13. Watch Solution: Filtering Data that is Displayed. Repeat her steps to learn how to use the filters.

Explanation / Answer

1. The five commonly accessed menu choices are : file, view, go, edit, capture, preference.

4. Time Display Format is under "view" choice.

5. The manufacturer of a NIC would be determined from "edit" or "preference" or "capture choice".

6. Reload option shouldn't be activated. If reload option is activated and we clicked on it the captured packet will get vanish.

7. Summary option is residing in File > Fileset > List Files. There are four options present: Filename, Created, Last Modified and Size.

8. Follow the steps to capture DNS packets:

9. If you want all the datail information of a port then capture filter shouldn't be considered.

10. Using expression builder you can compare values in packets as well as combine expressions into more specific expressions.

11. Follow the steps to acknowledge the flag set in tcp only