200-201 Network Intrusion Analysis • Set 11
200-201 Network Intrusion Analysis Practice Test 11 — 15 questions with explanations. Free, no signup.
During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.