CompTIA Network+ (N10-009)Network TroubleshootingHard
A security analyst wants to capture only HTTP traffic destined for port 80 on interface eth0 to investigate a possible plaintext credential leak. Which tcpdump command would accomplish this?
- Atcpdump -i eth0 --host 80
- Btcpdump -D eth0 tcp.port==80
- Ctcpdump -i eth0 -p 80 udp
- Dtcpdump -i eth0 port 80
Show answer & explanationAnswer & explanation
Correct answer: D. tcpdump -i eth0 port 80
The correct tcpdump syntax to capture traffic on a specific interface and filter by port is 'tcpdump -i <interface> port <number>'. This captures all traffic (both directions) on port 80, which is standard for HTTP.
Why the other options are wrong
- A. '--host' is not the correct syntax for a port filter; tcpdump uses 'port', not '--host', for this purpose.
- B. 'tcp.port==80' is Wireshark display filter syntax, not valid tcpdump capture filter syntax, and -D lists interfaces rather than selecting one.
- C. HTTP uses TCP, not UDP, and '-p' in tcpdump means non-promiscuous mode, not port specification.
tcpdump Syntax
A command-line packet analyzer used to capture and filter network traffic, using flags like -i for interface and BPF filter expressions like 'port'.
- -i specifies the capture interface (e.g., eth0)
- 'port 80' filters traffic on TCP or UDP port 80
- -D lists available capture interfaces rather than filtering traffic
- tcpdump uses BPF syntax, different from Wireshark display filter syntax
Memory trick: Interface first, then filter the port