Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-585 All Questions

View all questions & answers for the 156-585 exam

Exam 156-585 topic 1 question 59 discussion

Actual exam question from Checkpoint's 156-585
Question #: 59
Topic #: 1
[All 156-585 Questions]

What file extension should be used with fw monitor to allow the output file to be imported and read in WireShark?

  • A. .cap
  • B. .exe
  • C. .tgz
  • D. .pcap
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
hashpoc
1 month, 1 week ago
Selected Answer: A
All of the guides now use .pcap in the labs
upvoted 1 times
hashpoc
1 month, 1 week ago
Sorry i meant D for .pcap
upvoted 1 times
...
...
Freelancer
10 months, 2 weeks ago
fw monitor -e 'accept (src=172.25.16.14) or (dst=172.25.16.87);' -m iIoO -o wireshark.pcap
upvoted 1 times
...
thehill
1 year, 2 months ago
Selected Answer: A
It should be A. See question #70 or https://support.checkpoint.com/results/sk/sk30583. .pcap is the Wireshark format with which Wireshark saves its captures
upvoted 1 times
...
nmrouter
1 year, 3 months ago
Selected Answer: D
Correct answer is D, it should be pcap
upvoted 1 times
...
greeklover84
1 year, 5 months ago
Selected Answer: D
I think the best answer is .pcap see the reference below. https://www.wireshark.org/docs/wsdg_html_chunked/ChWorksCaptureFiles.html
upvoted 1 times
...
rlslima
1 year, 9 months ago
Selected Answer: A
When writing fw monitor packet capture data to a file, use the .cap extension in order for Wireshark to automatically associate with it.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...