Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A SOC analyst is analyzing a packet capture from a network where an internal host communicated with a known malicious IP. The analyst uses Wireshark and applies a display filter to isolate all HTTP traffic. Which filter expression should he use?

⚠ Common exam trap

Many candidates confuse display filters with capture filters or assume that HTTP traffic only uses port 80, leading them to choose 'tcp.port == 80' instead of the simpler and more comprehensive 'http' filter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

http

The correct filter is 'http' because in Wireshark, simply typing 'http' as a display filter captures all HTTP traffic, including both requests and responses. This is the most straightforward way to isolate all HTTP packets without limiting to a specific direction or port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    http.request

    Why it's wrong here

    The display filter 'http.request' is narrowly scoped to only HTTP request packets that contain a request line (e.g., GET, POST, PUT) and its associated method headers. It does not match HTTP responses, status lines, or response body packets, so a SOC analyst using it would miss the server's replies and headers. For comprehensive HTTP traffic analysis, you need a filter that captures both requests and responses, which the plain 'http' filter does.

  • ✗

    ip.proto == 6

    Why it's wrong here

    The filter 'ip.proto == 6' selects all IPv4 packets whose protocol field is 6, meaning every TCP segment regardless of the application-layer payload. This includes SSH, TLS, SMTP, and countless other TCP-based protocols, making it far broader than HTTP and utterly non-specific to web traffic. It also does not inspect the TCP payload to verify whether HTTP headers are present, so it cannot distinguish an HTTP conversation from any other TCP stream.

  • ✗

    tcp.port == 80

    Why it's wrong here

    Using 'tcp.port == 80' matches any TCP packet with source or destination port 80, but this is a header-level filter that ignores the actual payload contents. Port 80 can carry non-HTTP protocols, and HTTP can be served over non-standard ports, so the filter will produce both false positives and false negatives. Additionally, it includes TCP handshake, ACK, and retransmission packets that contain no HTTP data, adding noise that the 'http' protocol filter avoids by requiring real HTTP dissector activity.

  • ✓

    http

    Why this is correct

    The 'http' filter is correct because it selects every packet in which Wireshark's HTTP dissector successfully identifies HTTP protocol data, encompassing requests, responses, status lines, headers, and bodies. Unlike port-based filters, it is application-layer aware and verifies the presence of HTTP semantics, not just a well-known port number. This makes it the precise, protocol-specific filter an SOC analyst should use to capture the complete picture of HTTP traffic on the wire.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.