exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 35 discussion

Actual exam question from CompTIA's CS0-003
Question #: 35
Topic #: 1
[All CS0-003 Questions]

A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself. Which of the following can the analyst perform to see the entire contents of the downloaded files?

  • A. Change the display filter to ftp.active.port
  • B. Change the display filter to tcp.port==20
  • C. Change the display filter to ftp-data and follow the TCP streams
  • D. Navigate to the File menu and select FTP from the Export objects option
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nmap_king_22
Highly Voted 1 year, 8 months ago
Selected Answer: C
To see the entire contents of the downloaded files in the FTP session captured in Wireshark, the analyst should perform the following steps: C. Change the display filter to ftp-data and follow the TCP streams. By changing the display filter to "ftp-data" and then following the TCP streams, the analyst can access and view the entire data transfer, which includes the contents of the downloaded files. This method allows you to reconstruct and view the files being transferred over FTP
upvoted 20 times
...
BigFoot101T
Highly Voted 1 year, 4 months ago
Selected Answer: C
I chose and was confused, for everyone else who picked D here is the explanation from ChatGPT. It's pretty good. Option D (Navigate to the File menu and select FTP from the Export objects option) is not a direct method for viewing the file contents in the packet list pane. It's more related to extracting files from the capture, which might be useful but doesn't directly address the issue of viewing the file transfer in the current context.
upvoted 6 times
...
cy_analyst
Most Recent 7 months, 3 weeks ago
Selected Answer: D
In Wireshark, when dealing with FTP sessions, the control commands (such as RETR, STOR, and responses like 226 Transfer complete) are visible with the ftp filter. However, the actual file transfer data is sent over a separate data channel and is not displayed by default with just the ftp filter, as that mainly captures the control messages. To access the files transferred during the session, the analyst can go to File → Export Objects → FTP. This feature allows Wireshark to reconstruct and display any files transferred via FTP during the session, including those downloaded using RETR commands.
upvoted 2 times
...
m025
1 year, 2 months ago
Selected Answer: C
https://adrinanthony.wordpress.com/2019/07/19/how-to-extract-http-and-ftp-files-from-wireshark-pcap-file/
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago