CIS-534
Lab Assessment Questions & Answers
1. What are some causes of the number of bytes on the wire exceeding the number of bytes being captured?
2. What are the source and destination MAC address in Frame 546?
3. What is the manufacturer specific ID for Intel Core?
4. What is the MAC address used for IPv4 multicast?
5. What version of IP is present in Frame 546? What is the source IP address?
6. At what times did the various steps of the Google three step TCP handshake occur?
7. A DNS query failure is referred to a higher level Domain Name Server under what condition?
8. The descriptive text that accompanies the packet analysis is provided by Wireshark. True or False?
Lab Assessment Questions & Answers
1. Which tool, Wireshark or NetWitness, provides information about the wireless antenna strength during a captured transmission?
2. Which tool displays the MAC address and IP address information and allows them to be correlated for a given capture transmission?
3. What is the manufacturer specific ID for the GemTek radio transmitter/receiver?
4. The receiver and/or transmitter address is hard-coded in hardware and cannot be changed: it can always be counted on to correctly identify the device transmitting. True or False.
5. The actual web host name to which www.polito.it resolved was?
6. How can one determine that the website www.polito.it is in Italy?
7. What is the IP address for www.polito.it?
8. What destination organization is the owner of record of www.polito.it?
Lab Assessment Questions
1. TCP stands for?
2. UDP stands for?
3. The File Transfer Protocol (FTP) uses which transport protocol, TCP or UDP?
4. The PING diagnostic is part of which protocol?
5. TCP uses which Layer 3 protocol?
6. UDP uses which Layer 3 protocol?
7. Hyper Text Transfer Protocol (HTTP) and Secure HTTP (HTTPS) are the same protocol from a standpoint of passing or blocking them with a firewall. True or False?
8. A Host is defined as