Courseiva

200-201 Network Intrusion Analysis Practice Question

In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?

⚠ Common exam trap

It's easy for candidates to confuse IP-based filtering with stream-based filtering; candidates might think that filtering by IP address is sufficient to reconstruct a conversation, but it fails to separate multiple connections between the same hosts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

tcp.stream eq 0

The filter `tcp.stream eq 0` isolates all packets belonging to a specific TCP stream, identified by Wireshark's internal stream index. This allows you to reconstruct the full conversation between two hosts, including the three-way handshake, data transfer, and teardown. It is the standard method for following a TCP stream in Wireshark, as it groups packets by connection rather than just IP addresses or ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip.addr

    Why it's wrong here

    ip.addr filters packets by source or destination address, returning every protocol exchanged with those hosts rather than the single TCP stream. It is tempting because it narrows the capture to the two hosts of interest, which is the correct first step when you do not yet know which conversation or port to examine.

  • ✗

    http.request

    Why it's wrong here

    http.request matches only HTTP request packets, so it excludes the server responses and any non-HTTP traffic in the TCP conversation, preventing stream reassembly. It is tempting because it isolates web requests, which is the right filter when hunting for a specific outbound HTTP call rather than rebuilding a full bidirectional TCP session.

  • ✓

    tcp.stream eq 0

    Why this is correct

    The tcp.stream eq 0 filter isolates a single reassembled TCP conversation by its stream index, letting the analyst follow the full exchange between the two hosts. Following the stream reconstructs the session payload for forensic review.

  • ✗

    dns.qry.name

    Why it's wrong here

    dns.qry.name matches DNS query packets by queried name, returning name-resolution traffic rather than the TCP payload stream between the two hosts. It is tempting because it quickly isolates lookups for a suspicious domain, which is the correct filter when investigating DNS tunnelling or resolving which host contacted a malicious name.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.