XK0-006 Troubleshooting Practice Question
An administrator needs to capture network traffic on interface eth0, filtering only packets from host 192.168.1.1, and write the output to a file for later analysis. Which command accomplishes this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
tcpdump -i eth0 host 192.168.1.1 -w capture.pcap
tcpdump -i eth0 host 192.168.1.1 -w capture.pcap captures packets from the specified host on eth0 and writes to a file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tcpdump -i eth0 src 192.168.1.1 -w capture.pcap
Why it's wrong here
This captures only source, not both directions.
- ✗
tcpdump -i eth0 dst 192.168.1.1 > capture.pcap
Why it's wrong here
dst captures only destination, and redirect is not the proper way.
- ✓
tcpdump -i eth0 host 192.168.1.1 -w capture.pcap
Why this is correct
Correct: host captures both directions.
- ✗
tcpdump -n -i eth0 host 192.168.1.1 > capture.pcap
Why it's wrong here
> redirects text output, not binary pcap.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.