exam questions

Exam 412-79v8 All Questions

View all questions & answers for the 412-79v8 exam

Exam 412-79v8 topic 1 question 165 discussion

Actual exam question from ECCouncil's 412-79v8
Question #: 165
Topic #: 1
[All 412-79v8 Questions]

Wireshark is a network analyzer. It reads packets from the network, decodes them, and presents them in an easy-to-understand format. Which one of the following is the command-line version of Wireshark, which can be used to capture the live packets from the wire or to read the saved capture files?

  • A. Tcpdump
  • B. Capinfos
  • C. Tshark
  • D. Idl2wrs
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
testecsa
5 years, 1 month ago
TShark is a terminal oriented version of Wireshark designed for capturing and displaying packets when an interactive user interface isn’t necessary or available. It supports the same options as wireshark. For more information on tshark consult your local manual page (man tshark)
upvoted 2 times
...
hiron
5 years, 4 months ago
tcpdump
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...