Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is performing a network forensic investigation. The analyst needs to reconstruct a series of HTTP requests and responses from a PCAP file to understand user activity and potential data exfiltration. Which command-line tool is specifically designed for extracting and reassembling TCP/IP streams, including HTTP conversations, from a PCAP?

  1. AWireshark (CLI)
  2. Btshark
  3. Ctcpdump
  4. Dnetstat
Show answer & explanation

Correct answer: B. tshark

Tshark is the command-line version of Wireshark and is specifically designed for analyzing and extracting data from packet capture files, including the ability to reconstruct TCP/IP streams and display application-layer protocols like HTTP.

Why the other options are wrong

  • A. Wireshark (GUI) is excellent for this, but the question specifies a 'command-line tool'.
  • C. Tcpdump is primarily for capturing and displaying raw packet data, not for reassembling application-layer streams.
  • D. Netstat displays network connections, routing tables, and interface statistics on a live system, not for analyzing PCAP files.

Tshark

The command-line network protocol analyzer that is part of the Wireshark suite, used for capturing, displaying, and analyzing packet data from live networks or saved PCAP files.

  • Command-line version of Wireshark
  • Supports stream reassembly
  • Powerful filtering and export capabilities

Memory trick: PCAP Analysis: Tshark for CLI, Wireshark for GUI.

More Network Intrusion Analysis questions