WCA-101 Sample Questions & Answers
Breaking down protocols such as Ethernet, ARP and IPv4 packet by packet carries by far the most weight, next to troubleshooting protocol issues, filtering traffic with capture and display filters, different capture methods, Wireshark's core features, and its interface.
Launch the full WCA-101 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Utilize Key Features of Wireshark · File Operations and Export
During an incident response investigation, an analyst suspects malware was downloaded via unencrypted HTTP. They have a 10GB capture file and want to extract the actual executable file to their local disk for malware analysis. Which Wireshark feature is designed specifically for this task?
Show answer & explanation
Correct answer: A
The 'Export Objects' feature allows analysts to reconstruct and save files that were transferred over supported protocols (like HTTP, SMB, TFTP) directly to their local hard drive. This is the exact tool designed for extracting payloads like downloaded executables from a packet capture.
- Question 2Beginner
Utilize Key Features of Wireshark · Statistical Analysis Tools
True or False: In the Wireshark Packet Details pane, fields enclosed in square brackets (e.g., [SEQ/ACK analysis]) represent actual bytes captured directly from the network wire.
Show answer & explanation
Correct answer: B
In Wireshark, any field enclosed in square brackets [ ] indicates that the information was generated or calculated by Wireshark's protocol dissectors. These fields do not represent actual raw bytes captured from the network wire, but rather contextual information provided to assist the analyst (e.g., [Time since previous frame], [SEQ/ACK analysis]).
- Question 3Intermediate
Utilize Different Methods of Capturing Traffic · Capture Methods Comparison
A network engineer is preparing to capture traffic on a heavily utilized 10 Gbps full-duplex core switch link. They need to ensure that physical layer errors (like runts and CRCs) are captured and that no packets are dropped due to oversubscription. Which capture method is the BEST choice?
Show answer & explanation
Correct answer: A
A Hardware Network Tap is an inline physical device that copies all traffic, including physical layer errors (runts, CRCs, giants), directly to a monitoring port. Because a 10 Gbps full-duplex link can theoretically generate 20 Gbps of traffic, a properly sized Tap ensures zero dropped packets, unlike a SPAN port which can become oversubscribed and silently drop packets.
- Question 4Advanced
Utilize Different Methods of Capturing Traffic · Capture Management and CLI Tools
A systems administrator is troubleshooting an intermittent application timeout that occurs approximately once every three to four days. The traffic volume on the server is extremely high, generating around 50GB of data per hour. They need to capture the exact moment the failure occurs without exhausting the server's 500GB of available disk space. Which capture management strategy is required?
Show answer & explanation
Correct answer: B
A Ring Buffer allows Wireshark (or dumpcap) to capture continuously by splitting data into multiple files of a set size. Once the maximum number of files is reached, the oldest file is overwritten. This guarantees that the most recent traffic is always preserved without ever exhausting the 500GB of disk space. When the intermittent issue occurs, the admin stops the capture and reviews the latest files.
stateDiagram-v2 [*] --> File1 File1 --> File2: Reaches 1GB File2 --> File3: Reaches 1GB File3 --> File1: Overwrites oldest (Ring Buffer) - Question 5IntermediateSelect 2
Utilize Different Methods of Capturing Traffic · Capture Management and CLI Tools
An analyst needs to capture traffic continuously on a headless Linux server that has very limited RAM and CPU resources. They do not need to analyze the traffic in real-time on this server; they only need to write the raw packets to disk. Which TWO command-line tools are best suited for this lightweight capture task? (Select TWO)
Show answer & explanation
Correct answers: B, D
Dumpcap is the underlying packet capture engine for Wireshark and tshark. It is highly optimized, uses very little RAM and CPU, and its sole purpose is to capture packets and write them to disk without attempting to dissect or analyze them.
Tcpdump is a standard, lightweight, command-line packet analyzer available on almost all Linux distributions. When used with the -w flag, it writes raw packets directly to a pcap file with minimal resource overhead, making it ideal for headless servers.
- Question 6Beginner
Utilize Different Methods of Capturing Traffic · Capture Methods Comparison
A developer is troubleshooting a web application where both the frontend client and the backend database reside on the exact same physical server. To capture the traffic between them using Wireshark, which interface must be selected?
Show answer & explanation
Correct answer: D
When two applications on the same host communicate with each other, the operating system routes the traffic internally via the loopback interface (127.0.0.1 or ::1). This traffic never reaches the physical network card, so capturing on the physical Ethernet interface will yield zero packets between the two local applications.
Ready for the real thing?
The full WCA-101 simulator has every exam-style question, timed mode, and instant scoring.