Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy

A security analyst is using Wireshark to analyze a PCAP file. They need to quickly identify all packets associated with a specific TCP session to understand the full flow of communication. Which Wireshark feature would be most efficient for this task?

  1. AApplying a display filter for 'tcp.port == 80'
  2. BSorting packets by 'Time' column
  3. CUsing the 'Follow TCP Stream' option
  4. DExporting all packets to a CSV file
Show answer & explanation

Correct answer: C. Using the 'Follow TCP Stream' option

The 'Follow TCP Stream' feature in Wireshark automatically filters and reconstructs the entire conversation for a specific TCP session, presenting it in an easy-to-read format, which is exactly what's needed to understand a full flow.

Why the other options are wrong

  • A. Filtering by port shows all traffic on that port, not just a single TCP session.
  • B. Sorting by time helps with chronology but doesn't group packets by session or reconstruct the conversation content.
  • D. Exporting to CSV would dump metadata, not reconstruct the session content or filter it for a single flow.

Wireshark Follow TCP Stream

The 'Follow TCP Stream' feature in Wireshark allows an analyst to select a packet within a TCP conversation and then view all related packets in that specific session, often reconstructing the application-layer data exchanged.

  • Filters all packets for a single TCP session
  • Reconstructs the conversation content
  • Useful for understanding full data flows
  • Accessible via right-click on a TCP packet

Memory trick: Wireshark's 'Stream Follow' is like a detective tracing a single conversation through a crowd.

More Network Intrusion Analysis questions