Wireshark Certified Analyst Practice Questions
Prepare for WCA-101 with more than an answer.
- Exam fee
- $349 USD
- Time limit
- 120 minutes
- Questions on the exam
- 50-61
- Passing score
- Not publicly disclosed (determined by statistical analysis)
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Utilize Key Features of Wireshark10%
- Utilize Different Methods of Capturing Traffic10%
- Filter Traffic Using Capture and Display Filters12%
- Configure, Adapt, and Use the Wireshark Interface for Different Scenarios5%
- Identify and Explain Common Network Protocols Dissected by Wireshark43%
- Use Wireshark to Troubleshoot Common Issues with Protocols20%
- 1
When capturing traffic on a switched network using a SPAN port, the network interface card (NIC) on the capturing machine must be placed in ________ mode to ensure it processes frames not explicitly destined for its own MAC address.
Show answer details
Correct answer: A
Promiscuous mode tells the Network Interface Card (NIC) to pass all traffic it receives to the CPU/OS, regardless of the destination MAC address. Without promiscuous mode, the NIC's hardware filter drops any frames not addressed to its own MAC address, broadcast, or joined multicast groups.
- 2
Which of the following accurately describes a key difference between capture filters and display filters in Wireshark?
Show answer details
Correct answer: A
Capture filters use Berkeley Packet Filter (BPF) syntax (e.g., 'host 10.0.0.1') and are applied by the capture engine (libpcap/Npcap). Packets that don't match are dropped and never saved to disk. Display filters use Wireshark's syntax (e.g., 'ip.addr == 10.0.0.1') to dynamically show or hide packets that have already been saved to the capture file.
- 3
An analyst wants to filter out all traffic communicating with the IP address 10.0.0.5. They enter the display filter
ip.addr != 10.0.0.5. However, they notice that packets involving 10.0.0.5 are still appearing in the packet list. Why does this happen?Show answer details
Correct answer: B
The
ip.addrfield represents two underlying fields:ip.srcandip.dst. When using!=, Wireshark applies an implicit 'any' logic. It means "show this packet if ANY of the IP addresses present are NOT 10.0.0.5". To properly exclude all traffic to/from an IP, the correct syntax is!(ip.addr == 10.0.0.5)ornot ip.addr == 10.0.0.5. - 4
An analyst needs to share a capture file with a colleague and wants to add explanatory text to specific packets indicating where an anomaly begins. Which file format and approach must be used?
Show answer details
Correct answer: A
The pcapng (PCAP Next Generation) format supports advanced features not available in the legacy pcap format, including the ability to add comments to individual packets. If you try to add a packet comment in a standard pcap file, Wireshark will prompt you to save the file in pcapng format.
- 5
A network engineer is measuring the response time of a database server. They want to see the exact time elapsed between an SQL query packet and the corresponding SQL response packet. Which TWO time display formats or features would be most appropriate? (Select TWO)
Show answer details
Correct answer: B, C
If a display filter is applied to show only the specific query and its response, 'Seconds Since Previously Displayed Packet' (Delta Time) will show the exact time elapsed between the two packets.
Setting a Time Reference on the specific query packet resets the clock to zero for that packet. Any subsequent packets, including the response, will show the exact time elapsed since that specific query.
- 6
An incident response team receives a 5GB trace file containing raw traffic from a compromised network segment. Upon opening the file in Wireshark, the application becomes severely unresponsive, and the status bar indicates it is taking an abnormally long time to load. The analyst notices reverse DNS queries are actively leaving their workstation. What is the most effective way to resolve this performance issue?
Show answer details
Correct answer: D
When network name resolution is enabled, Wireshark attempts to resolve every unique IP address in the capture file to a hostname by querying the local DNS server. In a 5GB file with thousands of unique IPs, this generates massive concurrent DNS queries, causing severe interface lag and potential network congestion. Disabling it immediately restores performance.
flowchart TD A[Open 5GB PCAP] --> B{Network Name Resolution Enabled?} B -->|Yes| C[Wireshark sends thousands of DNS PTR queries] C --> D[Application freezes waiting for DNS timeouts] B -->|No| E[IP addresses displayed natively] E --> F[Fast loading and analysis]
