Reference no: EM131188394
Lab: Performing Packet Capture and Traffic Analysis
Overview
In this lab, you used common applications to generate traffic and transfer files between the machines in this lab. You captured data using Wireshark and reviewed the captured traffic at the packet level, and then you used NetWitness Investigator, a free tool that provides security practitioners with a means of analyzing a complete packet capture, to review the same traffic at a consolidated level.
Lab Assessment Questions & Answers
1. Why would a network administrator use Wireshark and NetWitness Investigator together?
2. What was the IP address for LanSwitch1?
3. When the 172.16.8.5 IP host responded to the ICMP echo-requests, how many ICMP echo-reply packets were sent back to the vWorkstation?
4. What was the terminal password for LanSwitch 1 and LanSwitch 2?
5. When using SSH to remotely access a Cisco router, can you see the terminal password? Why or why not?
6. What were the Destination IP addresses discovered by the NetWitness Investigator analysis?
7. Are packet-capturing tools like Wireshark less dangerous on switched LANs?
Support the negotiation process
: Discuss how selecting the right team members can support the negotiation process?
|
Describe what is the purpose of the business impact analysis
: What is the purpose of the business impact analysis (BIA)? What is the difference between a disaster recovery plan (DRP) and a business continuity plan (BCP)?
|
Flexible flexible static enrollment-utilization enrollment
: Here are the 2015 revenues for Nu-Kim Radiology for four different budgets: Flexible Flexible Static Enrollment & Utilization Enrollment Actual Budget Budget Budget Results $200,000 $204,000 $176,000 184,000. Revenue Variance = b. Volume Variance = c..
|
Write a memo to your manager
: Write a memo to your manager giving your thoughts on how this should be handled by the client and how should company F report the above facts on its December 31, 20XX balance sheet and income statement?
|
Why would a network administrator use wireshark
: Why would a network administrator use Wireshark and NetWitness Investigator together? When the 172.16.8.5 IP host responded to the ICMP echo-requests, how many ICMP echo-reply packets were sent back to the vWorkstation?
|
Calculate each projects payback period-NPV and IRR
: You have been retained as a management consultant by a local specialty retailer, to analyze two proposed capital investment projects, projects X and Y. Project X is a sophisticated working capital and inventory control system server, specifically des..
|
What sources could you use as a source to perform the mbsa
: What is the minimum password length enforced by the Password must meet complexity requirements policy? What sources could you use as a source to perform the MBSA security scan?
|
What are the fundamental elements of an effective security
: What are the three fundamental elements of an effective security program for information systems? Of these three fundamental controls, which two are used by the Domain User Admin to create users and assign rights to resources?
|