Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security analyst is using Wireshark to analyze a PCAP file. They need to quickly identify all packets associated with a specific TCP session to understand the full flow of communication. Which Wireshark feature would be most efficient for this task?
- AApplying a display filter for 'tcp.port == 80'
- BSorting packets by 'Time' column
- CUsing the 'Follow TCP Stream' option
- DExporting all packets to a CSV file
Show answer & explanationAnswer & explanation
Correct answer: C. Using the 'Follow TCP Stream' option
The 'Follow TCP Stream' feature in Wireshark automatically filters and reconstructs the entire conversation for a specific TCP session, presenting it in an easy-to-read format, which is exactly what's needed to understand a full flow.
Why the other options are wrong
- A. Filtering by port shows all traffic on that port, not just a single TCP session.
- B. Sorting by time helps with chronology but doesn't group packets by session or reconstruct the conversation content.
- D. Exporting to CSV would dump metadata, not reconstruct the session content or filter it for a single flow.
Wireshark Follow TCP Stream
The 'Follow TCP Stream' feature in Wireshark allows an analyst to select a packet within a TCP conversation and then view all related packets in that specific session, often reconstructing the application-layer data exchanged.
- Filters all packets for a single TCP session
- Reconstructs the conversation content
- Useful for understanding full data flows
- Accessible via right-click on a TCP packet
Memory trick: Wireshark's 'Stream Follow' is like a detective tracing a single conversation through a crowd.