Question 1

Null scans use legal TCP packet formats, but listen for illegally-formed TCP response packets.
  • Question 2

    Columns can be reordered by dragging them into their new positions directly in the Packet List pane.
  • Question 3

    By default, Mergecap combinestrace files based on the order they are listed on the command-line.
  • Question 4

    You can force Wireshark to temporarily dissect traffic to and fromport 18067 as IRC traffic using the Decode As function.
  • Question 5

    You are performing a TCP scan on a target while capturing your traffic with Wireshark. Which statement about the analysis is correct?