A security analyst is reviewing a packet capture in wireshar - CompTIA CySA+ CSO-003

Question

A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself. Which of the following can the analyst perform to see the entire contents of the downloaded files?

Answers
  1. correct
Explanation

The correct answer is: C. Change the display filter to ftp-data and follow the TCP streams

  • This is the correct answer because ftp-data refers to the data channel used in an FTP session for transferring files. In FTP, there are two channels: the control channel (usually on port 21) for sending commands (like RETR) and the data channel for transferring actual files.
  • When a file is transferred, it's done through the data channel (ftp-data), which is often on a dynamic port, and Wireshark might not show the data packets by default with just a filter on ftp. By changing the filter to ftp-data, the analyst can see the actual file transfer packets. Using the "Follow TCP Stream" option will allow the analyst to view the entire content of the transferred file in the conversation.

Why the Other Options Are Incorrect:

Change the display filter to ftp.active.port

  • This is incorrect because ftp.active.port is not a standard Wireshark display filter. FTP typically operates using a dynamic port for the data transfer in active mode, but this filter would not specifically isolate the file transfer data. It's not the most effective approach to view the file content.

Change the display filter to tcp.port==20

  • This is incorrect because TCP port 20 is commonly used for FTP data in active mode, but it is not a definitive filter for capturing the data channel in modern FTP sessions, especially if passive mode (using dynamic ports) is being used for the file transfer. Filtering by TCP port 20 will only show traffic related to FTP data transfers in active mode, and it might miss passive mode traffic.

Navigate to the File menu and select FTP from the Export objects option

  • This is incorrect because the Export Objects option in Wireshark is typically used to extract files from HTTP or other protocols where objects are explicitly served by the server. FTP file transfers do not work in the same manner as HTTP, so this option would not apply to FTP sessions, and it won't show the contents of the files that were transferred.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered