Questions
Now, it's time to check your knowledge. Fill in the blanks from the multiple choices and then check your answers, which can be found in the Assessments appendix:
- _____ is a capture engine originally developed for Unix-like OSes and is baked into Snort, TCPDUMP, and other packet analyzers to grab packets as they come off the network interface:
- Capinfos
- MATE
- libpcap
- Transum
- Radiotap headers can be used when troubleshooting Wi-Fi, as they can provide a lot of information associated with each _____frame:
- 802.3
- 802.15
- 802.11
- 802.8
- _____ is a program that will identify and print a packet's geolocation by using IPv4 and IPv6 addresses:
- dftest
tshark
- mergecap
- mmdbresolve
- _____ is the newest capture engine option for Wireshark, with many benefits and features to enhance your packet capture:
- AirPcap
- Npcap
- WinPcap
- libpcap
- One of Wireshark's tools, _____ allows you to adjust timestamps, delete packets, and convert file formats:
- Editcap
- Capinfos
- dftest
- Reordercap
...