exam questions

Exam CWAP-402 All Questions

View all questions & answers for the CWAP-402 exam

Exam CWAP-402 topic 1 question 23 discussion

Actual exam question from CWNP's CWAP-402
Question #: 23
Topic #: 1
[All CWAP-402 Questions]

When using Wireshark for protocol analysis, what filter will allow you to see only beacon frames?

  • A. wlan.fc.type_subtype = =0x05
  • B. wlan.fc.type_subtype = =0x0b
  • C. wlan.fc.type_subtype = =0x08
  • D. wlan.fc.type_subtype = =0x04
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
http://www.lovemytool.com/blog/2010/02/wireshark-wireless-display-and-capture-filters-samples-by-joke-snelders.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tonydiamond
5 months ago
Selected Answer: C
wlan.fc.type_subtype == 0x8 is the expression which we need to add in the filter box. The reason why we are comparing it with 0x8 is, beacons are part of the management frames which has the type field set to 0 and beacons are represented by a hex value of 0x8 i.e there sub-type is 8. We can change the sub-type alone and map them to any one of the other management frames. For example the above filter can be modified to show only probe request frames with this expression wlan.fc.type_subtype == 0x5 and wlan.fc.type_subtype == 0x6 goes for probe response frames.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago