200-201 Security Monitoring Practice Question
In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?
⚠ Common exam trap
Watch out — candidates often confuse FTP with SFTP or assuming that all file transfer protocols are encrypted; candidates might overlook that FTP sends credentials in plaintext while SFTP and FTPS do not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FTP
FTP (File Transfer Protocol) transmits data, including login credentials, in cleartext over TCP. When an analyst follows a TCP stream in Wireshark and sees plaintext usernames and passwords, it indicates that no encryption is applied. HTTPS, SFTP, and SSH all encrypt their payloads, so credentials would not be visible in plaintext. Therefore, FTP is the likely protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTPS
Why it's wrong here
HTTPS wraps HTTP in TLS, so the stream payload is encrypted and credentials are unreadable. It is tempting because it carries login forms, but the visible plaintext credentials indicate an unencrypted protocol such as HTTP, FTP or Telnet.
- ✗
SFTP
Why it's wrong here
SFTP runs over SSH and encrypts all traffic, so credentials would not appear as plaintext in a followed stream. It is tempting as a file-transfer login protocol, but the readable usernames and passwords point to unencrypted FTP instead.
- ✓
FTP
Why this is correct
FTP transmits credentials in cleartext over TCP, so a followed stream exposes usernames and passwords directly. Unlike FTPS or SFTP, which negotiate TLS or SSH encryption before authentication, plain FTP offers no confidentiality, matching the plaintext credentials observed in the capture.
- ✗
SSH
Why it's wrong here
SSH encrypts the entire session, so following its TCP stream would reveal ciphertext, not readable credentials. It is tempting because SSH is used for remote login, but the plaintext credentials indicate Telnet or FTP instead.
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.