PT0-002 Vulnerability Discovery and Analysis Practice Question
Which tool would be best for capturing and analyzing network packets to troubleshoot a web application?
⚠ Common exam trap
It's easy for candidates to confuse Burp Suite (a web application proxy) with a packet analyzer, but Burp Suite operates at the application layer and does not capture raw network packets or provide low-level protocol analysis like Wireshark does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wireshark
Wireshark is the correct tool because it is designed specifically for deep packet inspection, allowing you to capture live network traffic and analyze individual packets at multiple OSI layers. For troubleshooting a web application, you can filter HTTP/HTTPS requests and responses, examine TCP handshakes, and identify latency or payload issues, which is essential for diagnosing performance or functional problems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap is an active network scanning tool that sends crafted probes—such as TCP SYN scans and ICMP echo requests—to identify open ports, running services, and operating systems. It does not passively capture traffic from a network segment, nor does it decode or analyze packet contents like a dedicated sniffer. Its --packet-trace option only reveals packets it sends/receives during the scan, not general network communication.
- ✓
Wireshark
Why this is correct
Wireshark is a full-featured packet analyzer that captures frames in promiscuous mode via libpcap/WinPcap and dissects hundreds of protocols across all OSI layers. It supports live capture and offline analysis, with powerful display filters, color coding, TCP stream reassembly, and expert information to identify anomalies. This makes it the standard tool for traffic capture and analysis.
- ✗
Burp Suite
Why it's wrong here
Burp Suite is an intercepting web proxy that manipulates HTTP/HTTPS traffic between a client and server, enabling attackers to tamper with requests, replay them, and fuzz parameters. It operates at the application layer and requires a browser or app to be configured to route through it, so it neither sees raw Layer 2/3 packets nor captures non-HTTP protocols like DNS, SMTP, or SSH. Thus it cannot perform general network packet analysis.
- ✗
Aircrack-ng
Why it's wrong here
Aircrack-ng comprises a set of utilities for assessing wireless LAN security, including airodump-ng for collecting raw 802.11 frames and aircrack-ng for cracking WEP/WPA keys via captured handshakes. While it can capture Wi-Fi traffic, its focus is narrowly on wireless encryption attacks, not on decoding arbitrary network protocols or analyzing traffic from wired or other link types. It lacks the protocol dissectors and analysis features needed for comprehensive packet inspection.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.