Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?

⚠ Common exam trap

Watch out — candidates often confuse FTP with SFTP or assuming that all file transfer protocols are encrypted; candidates might overlook that FTP sends credentials in plaintext while SFTP and FTPS do not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FTP

FTP (File Transfer Protocol) transmits data, including login credentials, in cleartext over TCP. When an analyst follows a TCP stream in Wireshark and sees plaintext usernames and passwords, it indicates that no encryption is applied. HTTPS, SFTP, and SSH all encrypt their payloads, so credentials would not be visible in plaintext. Therefore, FTP is the likely protocol.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTPS

    Why it's wrong here

    HTTPS wraps HTTP in TLS, so the stream payload is encrypted and credentials are unreadable. It is tempting because it carries login forms, but the visible plaintext credentials indicate an unencrypted protocol such as HTTP, FTP or Telnet.

  • ✗

    SFTP

    Why it's wrong here

    SFTP runs over SSH and encrypts all traffic, so credentials would not appear as plaintext in a followed stream. It is tempting as a file-transfer login protocol, but the readable usernames and passwords point to unencrypted FTP instead.

  • ✓

    FTP

    Why this is correct

    FTP transmits credentials in cleartext over TCP, so a followed stream exposes usernames and passwords directly. Unlike FTPS or SFTP, which negotiate TLS or SSH encryption before authentication, plain FTP offers no confidentiality, matching the plaintext credentials observed in the capture.

  • ✗

    SSH

    Why it's wrong here

    SSH encrypts the entire session, so following its TCP stream would reveal ciphertext, not readable credentials. It is tempting because SSH is used for remote login, but the plaintext credentials indicate Telnet or FTP instead.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.