200-201 Network Intrusion Analysis Practice Question
In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?
⚠ Common exam trap
It's easy for candidates to confuse IP-based filtering with stream-based filtering; candidates might think that filtering by IP address is sufficient to reconstruct a conversation, but it fails to separate multiple connections between the same hosts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
tcp.stream eq 0
The filter `tcp.stream eq 0` isolates all packets belonging to a specific TCP stream, identified by Wireshark's internal stream index. This allows you to reconstruct the full conversation between two hosts, including the three-way handshake, data transfer, and teardown. It is the standard method for following a TCP stream in Wireshark, as it groups packets by connection rather than just IP addresses or ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip.addr
Why it's wrong here
ip.addr filters packets by source or destination address, returning every protocol exchanged with those hosts rather than the single TCP stream. It is tempting because it narrows the capture to the two hosts of interest, which is the correct first step when you do not yet know which conversation or port to examine.
- ✗
http.request
Why it's wrong here
http.request matches only HTTP request packets, so it excludes the server responses and any non-HTTP traffic in the TCP conversation, preventing stream reassembly. It is tempting because it isolates web requests, which is the right filter when hunting for a specific outbound HTTP call rather than rebuilding a full bidirectional TCP session.
- ✓
tcp.stream eq 0
Why this is correct
The tcp.stream eq 0 filter isolates a single reassembled TCP conversation by its stream index, letting the analyst follow the full exchange between the two hosts. Following the stream reconstructs the session payload for forensic review.
- ✗
dns.qry.name
Why it's wrong here
dns.qry.name matches DNS query packets by queried name, returning name-resolution traffic rather than the TCP payload stream between the two hosts. It is tempting because it quickly isolates lookups for a suspicious domain, which is the correct filter when investigating DNS tunnelling or resolving which host contacted a malicious name.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.