200-201 › Network Intrusion Analysis
This domain covers reading packets and logs to spot malicious activity: using tools like Wireshark and tcpdump to pull files from PCAPs, recognizing exfiltration and command-and-control patterns in DNS, FTP, and HTTP traffic, and mapping observed behavior to the Cyber Kill Chain. Questions give you a traffic scenario and ask for the correct interpretation or tool.
200-201 Network Intrusion Analysis — All 169 Questions
Every question in this domain with answers and detailed explanations.