Drag steps to the numbered slots on the right, or tap a step then tap a slot.
200-201 Practice Question: Drag and drop the steps to analyze a packet…
Drag and drop the steps to analyze a packet capture for suspicious activity into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Open the packet capture, then Filter the traffic, then Examine the packets, then Correlate findings, then Document results.
The correct sequence for packet capture analysis starts by opening the capture file, then applying filters to isolate relevant traffic, examining the filtered packets for anomalies, correlating findings across different packets or sessions, and finally documenting the analysis results for reporting and future reference. This order ensures efficiency and accuracy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Open the packet capture, then Filter the traffic, then Examine the packets, then Correlate findings, then Document results.
Why this is correct
This is the correct order because it follows a logical workflow: first access the data, reduce noise, inspect relevant packets, connect evidence, and finally record findings.
- ✗
Open the packet capture, then Examine the packets, then Filter the traffic, then Correlate findings, then Document results.
Why it's wrong here
This is incorrect because examining packets before filtering would overwhelm the analyst with irrelevant data; filtering should precede detailed inspection.
- ✗
Open the packet capture, then Filter the traffic, then Document results, then Examine the packets, then Correlate findings.
Why it's wrong here
This is incorrect because documenting findings before examining and correlating would lead to incomplete or inaccurate records; documentation should occur after analysis.
- ✗
Document results, then Correlate findings, then Examine the packets, then Filter the traffic, then Open the packet capture.
Why it's wrong here
This is incorrect because it reverses the entire process; analysis cannot begin by documenting results before even opening the capture.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.