exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 37 discussion

Actual exam question from CompTIA's PT0-002
Question #: 37
Topic #: 1
[All PT0-002 Questions]

A penetration tester received a .pcap file to look for credentials to use in an engagement.
Which of the following tools should the tester utilize to open and read the .pcap file?

  • A. Nmap
  • B. Wireshark
  • C. Metasploit
  • D. Netcat
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RRabbit_111
Highly Voted 2 years, 3 months ago
Selected Answer: B
B. Wireshark Wireshark is a free and open-source packet analyzer. It is used to capture, analyze, and inspect network traffic. One of its main features is its ability to read and interpret .pcap files, which are used to store captured network traffic. The tester can use Wireshark to open the .pcap file and analyze the network traffic to find credentials such as usernames and passwords that can be used during the engagement. Nmap is a network scanner and mapping tool, it can't be used to open and read .pcap files. Metasploit is a framework for exploiting vulnerabilities and performing penetration testing, it can't be used to open and read .pcap files. Netcat is a tool that can be used to read and write data across networks, it can't be used to open and read .pcap files.
upvoted 6 times
mad755
2 years, 1 month ago
my good samaritan, thank you for your comments. always informational and helpful.
upvoted 2 times
...
...
pizzaThyme
Most Recent 8 months, 2 weeks ago
Selected Answer: B
It's B. .pcap is read by WireShark. pcap stands for Packet Capture, which is the output of network sniffing done by wireshark.
upvoted 2 times
...
bieecop
1 year, 9 months ago
Selected Answer: B
To open and read a .pcap file, the penetration tester should utilize a tool like a. Wireshark. Wireshark is a popular and powerful network protocol analyzer that allows for the analysis and inspection of network traffic captured in various file formats, including .pcap files. It provides a graphical user interface (GUI) that allows the tester to view and analyze the captured packets, filter and search for specific data, and extract information such as credentials or other sensitive data.
upvoted 1 times
...
dcyberguy
2 years, 4 months ago
Selected Answer: B
It just got to be Wireshark
upvoted 3 times
...
petercorn
2 years, 6 months ago
Selected Answer: B
The .pcap file extension is mainly associated with Wireshark; a program used for analyzing networks. .pcap files are data files created using the program and they contain the packet data of a network. These files are mainly used in analyzing the network characteristics of a certain data. These files also contribute to successfully controlling traffic of a certain network since they are being monitored by the program.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago