CompTIA Network+ (N10-009)Network TroubleshootingHard

A security analyst wants to capture only HTTP traffic destined for port 80 on interface eth0 to investigate a possible plaintext credential leak. Which tcpdump command would accomplish this?

  1. Atcpdump -i eth0 --host 80
  2. Btcpdump -D eth0 tcp.port==80
  3. Ctcpdump -i eth0 -p 80 udp
  4. Dtcpdump -i eth0 port 80
Show answer & explanation

Correct answer: D. tcpdump -i eth0 port 80

The correct tcpdump syntax to capture traffic on a specific interface and filter by port is 'tcpdump -i <interface> port <number>'. This captures all traffic (both directions) on port 80, which is standard for HTTP.

Why the other options are wrong

  • A. '--host' is not the correct syntax for a port filter; tcpdump uses 'port', not '--host', for this purpose.
  • B. 'tcp.port==80' is Wireshark display filter syntax, not valid tcpdump capture filter syntax, and -D lists interfaces rather than selecting one.
  • C. HTTP uses TCP, not UDP, and '-p' in tcpdump means non-promiscuous mode, not port specification.

tcpdump Syntax

A command-line packet analyzer used to capture and filter network traffic, using flags like -i for interface and BPF filter expressions like 'port'.

  • -i specifies the capture interface (e.g., eth0)
  • 'port 80' filters traffic on TCP or UDP port 80
  • -D lists available capture interfaces rather than filtering traffic
  • tcpdump uses BPF syntax, different from Wireshark display filter syntax

Memory trick: Interface first, then filter the port

More Network Troubleshooting questions