Courseiva

200-201 Network Intrusion Analysis Practice Question

During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?

⚠ Common exam trap

The trap here is choosing a directional filter or an OR combination, when the goal is a two-host bidirectional conversation that requires both addresses joined with AND.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip.addr == 10.10.5.20 && ip.addr == 203.0.113.77

Repeating the address field with the AND operator restricts output to packets where the two addresses appear in either direction, which captures the full bidirectional conversation. A direction-specific filter hides responses, adding a port constraint may exclude the actual traffic, and using OR broadens the result to unrelated hosts. The bidirectional address pair is the reliable way to isolate one conversation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ip.addr == 10.10.5.20 && ip.addr == 203.0.113.77

    Why this is correct

    Using ip.addr twice with the AND operator matches packets where either field equals the first address and either field equals the second, effectively isolating bidirectional traffic between the two hosts. This is the standard way to view a conversation regardless of direction, which is exactly what the analyst needs when the role of client and server may vary during the exchange.

  • ✗

    ip.src == 10.10.5.20 && ip.dst == 203.0.113.77

    Why it's wrong here

    Restricting the filter to source and destination in one direction hides all return traffic from the suspect host. The analyst would see only outbound packets and could miss server responses, resets, or data exfiltration acknowledgments that are essential to judging whether the communication succeeded. For a full conversation view, direction-specific filters are too narrow.

  • ✗

    ip.addr == 10.10.5.20 || ip.addr == 203.0.113.77

    Why it's wrong here

    The OR operator returns every packet involving either address, including unrelated conversations each host had with other systems. This produces a noisy capture that defeats the purpose of isolating the specific conversation. To narrow to a single pair of endpoints, both conditions must be required together with AND rather than OR.

  • ✗

    tcp.port == 445 && ip.addr == 10.10.5.20

    Why it's wrong here

    This filter narrows the capture to a single port and one host, which may exclude the actual conversation if the malicious traffic used a different port. It also fails to constrain the remote endpoint, so traffic to any other host on that port would appear. Port assumptions are risky during investigations because attackers routinely use nonstandard ports.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.