A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself. Which of the following can the analyst perform to see the entire contents of the downloaded files?
The correct answer is: C. Change the display filter to ftp-data and follow the TCP streams
ftp. By changing the filter to ftp-data, the analyst can see the actual file transfer packets. Using the "Follow TCP Stream" option will allow the analyst to view the entire content of the transferred file in the conversation.Why the Other Options Are Incorrect:
Change the display filter to ftp.active.port
Change the display filter to tcp.port==20
Navigate to the File menu and select FTP from the Export objects option
No Payment Cards Needed
Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.
You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams