Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco Exam 300-215 Topic 7 Question 68 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 68
Topic #: 7
[All 300-215 Questions]

Refer to the exhibit.

A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the Wireshark traffic logs?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

I was thinking B) tls.handshake.type ==1 might be the right answer, since the Ursnif malware is likely using encrypted communication. But you make a good point, A) is probably the best choice here.
upvoted 0 times
...
Jolanda
2 days ago
I'm pretty sure the answer is A) http.request.un matches. The question is specifically asking about the HTTP request that triggered the Ursnif download, so that filter seems like the most relevant one.
upvoted 0 times
...
Truman
13 days ago
But the question specifically mentions analyzing the HTTP request, so A) seems more relevant.
upvoted 0 times
...
Berry
14 days ago
I disagree, I believe the correct answer is B) tls.handshake.type ==1.
upvoted 0 times
...
Truman
15 days ago
I think the answer is A) http.request.un matches.
upvoted 0 times
...
Davida
18 days ago
But the question specifically mentions analyzing the HTTP request, so A) seems more relevant.
upvoted 0 times
...
Shanice
21 days ago
I disagree, I believe the correct answer is B) tls.handshake.type ==1.
upvoted 0 times
...
Davida
24 days ago
I think the answer is A) http.request.un matches.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77