• Home
  • Textbooks
  • A Practical Guide to Advanced Networking
  • Analyzing Network Data Traffic

A Practical Guide to Advanced Networking

Jeffrey S. Beasley, Piyasat Nilkaew

Chapter 6

Analyzing Network Data Traffic - all with Video Answers

Educators


Chapter Questions

01:21

Problem 1

What is an Internet socket?

Pankaj Jain
Pankaj Jain
Numerade Educator

Problem 2

What is network forensics?

Check back soon!

Problem 3

What are well-known ports?

Check back soon!
04:00

Problem 4

Identify the port numbers for the following applications:
a. Telnet
b. HTTP
c. $\mathrm{FTP}$
d. DNS
e. $\mathrm{DHCP}$

Samriddhi Singh
Samriddhi Singh
Numerade Educator
01:45

Problem 5

Define the purpose of a connection-oriented protocol. Give an example.

Jennifer Stoner
Jennifer Stoner
Numerade Educator

Problem 6

What three packets are exchanged between two hosts when establishing a TCP connection?

Check back soon!

Problem 7

What is the purpose of a sequence number (SEQ=) in TCP data packets?

Check back soon!

Problem 8

Explain how a host knows whether a data packet was not received.

Check back soon!
01:45

Problem 9

Describe how a TCP connection is terminated.

Jennifer Stoner
Jennifer Stoner
Numerade Educator
01:45

Problem 10

What is a connectionless protocol? Give an example.

Jennifer Stoner
Jennifer Stoner
Numerade Educator
01:46

Problem 11

What is the SYN-SENT state?

Rachel Vallejo
Rachel Vallejo
Numerade Educator
01:46

Problem 12

What is the SYN-RECEIVED state?

Rachel Vallejo
Rachel Vallejo
Numerade Educator

Problem 13

What is the purpose of an ARP request?

Check back soon!

Problem 14

This state indicates that the three-packet handshake established a TCP connection.

Check back soon!

Problem 15

What is the FIN-WAIT-1 state, and where is it used?

Check back soon!

Problem 16

In this state, the terminating host acknowledges the last FIN and waits for the connection to close.

Check back soon!

Problem 17

In this TCP Connection state, the host is listening and ready to accept connections.

Check back soon!
01:37

Problem 18

In this TCP Connection state, the receiving host acknowledges the FIN.

James Kiss
James Kiss
Numerade Educator

Problem 19

In this TCP Connection State, the terminating host receives the acknowledgment from the receiving host.

Check back soon!
03:22

Problem 20

The netstat -an command is issued. What does the following indicate?
$$
\text { TCP } 0.0 .0 .0: 22
$$
$$
0.0 .0 .0: 0
$$
LISTENING

Jennifer Stoner
Jennifer Stoner
Numerade Educator
03:22

Problem 21

The netstat -an command is issued. What does the following indicate?
TCP 172.16.101.7:49192 199.7.59.72:80 TIME_WAIT

Jennifer Stoner
Jennifer Stoner
Numerade Educator

Problem 22

What is the purpose of an ARP reply?

Check back soon!

Problem 23

What command is used to view the ARP cache?

Check back soon!

Problem 24

What command can be used to display the age of each ARP entry?

Check back soon!

Problem 25

What important networking-troubleshooting tool is part of ICMP, and how does it test a network connection?

Check back soon!

Problem 26

What is the purpose of the ICMP message type 0 ?

Check back soon!

Problem 27

What ICMP message type is Time Exceeded?

Check back soon!

Problem 28

What is the purpose of the ICMP message type 8 ?

Check back soon!
00:23

Problem 29

Expand the acronym $A R P$.

Dale Sanford
Dale Sanford
Numerade Educator

Problem 30

What is the purpose of an ARP request?

Check back soon!
01:00

Problem 31

Expand the acronym ICMP.

Shahina -
Shahina -
Numerade Educator
01:03

Problem 32

What is an echo request?

Narayan Hari
Narayan Hari
Numerade Educator

Problem 33

What is the purpose of a protocol analyzer?
Included on the companion CD-ROM in the Wireshark capture file folder is a network packet capture file called PacketI Ia.cap. Open this file using Wireshark. The following five questions refer to this file.

Check back soon!

Problem 34

What are the MAC addresses of the computers involved?

Check back soon!

Problem 35

Which IP addresses correspond to each MAC address?

Check back soon!

Problem 36

Which packet IDs correspond to ARP requests?

Check back soon!

Problem 37

Which packet IDs correspond to ARP replies?

Check back soon!

Problem 38

Which computers are pinging which computers?

Check back soon!

Problem 39

In terms of computer security, a switch offers better security than a hub. Why is this?

Check back soon!

Problem 40

What is the management information base?

Check back soon!

Problem 41

What port does SNMP use and what transport protocol?

Check back soon!

Problem 42

The SNMP MIB get request ifDescr returns what information from a router?

Check back soon!
02:05

Problem 43

What is the purpose of the MIB?

Rabeya Zahid
Rabeya Zahid
Numerade Educator

Problem 44

Write the Cisco router command for configuring SNMP on a Cisco router. Assume a community string of networking and set the permissions to read-only. Show the router prompt.

Check back soon!

Problem 45

The command show run is entered on a Cisco router. Describe what the output "SNMP-server test RO" means.

Check back soon!

Problem 46

What SNMP MIBs were most likely issued to the router discussed in Section 6-4?

Check back soon!
02:02

Problem 47

Use Figure 6-38 to answer questions 47 to 51.
FIGURE 6-38 For problems 47–can't copy
What MIB was issued?

Barsha Rana
Barsha Rana
Numerade Educator
00:26

Problem 48

Use Figure 6-38 to answer questions 47 to 51.
FIGURE 6-38 For problems 47–can't copy..
What information was returned?

Wesley Hines
Wesley Hines
Numerade Educator
00:34

Problem 49

Use Figure 6-38 to answer questions 47 to 51.
FIGURE 6-38 For problems 47–can't copy.
What port number was used?

Wesley Hines
Wesley Hines
Numerade Educator
01:06

Problem 50

Use Figure 6-38 to answer questions 47 to 51.
FIGURE 6-38 For problems 47–can't copy.
What protocol is being used? How do you know?

Carson Merrill
Carson Merrill
Numerade Educator

Problem 51

Use Figure 6-38 to answer questions 47 to 51.
FIGURE 6-38 For problems 47–can't copy.
Who is the manufacturer of this networking device?

Check back soon!
01:44

Problem 52

What is the advantage of SNMPv3?

Qudsiya Anis
Qudsiya Anis
Numerade Educator

Problem 53

What security features are provided with SNMPv3?

Check back soon!

Problem 54

What is confidentiality?

Check back soon!

Problem 55

What is integrity relative to security?

Check back soon!

Problem 56

What is authentication relative to security?

Check back soon!

Problem 57

What is the purpose of NetFlow?

Check back soon!

Problem 58

What is the purpose of the collector when used with "flow" technologies.

Check back soon!

Problem 59

What is the following command doing?
RouterA (config)\# ip flow-export source Loopback0

Check back soon!

Problem 60

What is the purpose of the command ip route-cache flow?

Check back soon!

Problem 61

What command is used to display the NetFlow information?

Check back soon!

Problem 62

What does the following command do?
RouterA (config) \# ip flow-export version 5

Check back soon!

Problem 63

What is the purpose of the following command?
RouterA (config)\# ip flow-export destination 10.10.101.19 5000

Check back soon!

Problem 64

A filter with the ip.addr $=\mathbf{=} \mathbf{1 0 . 1 0 . 1 0 . 1}$ filter is applied to captured network data traffic. What happens?

Check back soon!
02:58

Problem 65

What filter could be used to display on data packets containing the IP address $192.168 .12 .5 ?$

Samriddhi Singh
Samriddhi Singh
Numerade Educator

Problem 66

What filter could be used to only display data files containing the FTP protocol?

Check back soon!

Problem 67

What is the purpose of the FTP-DATA filter?

Check back soon!

Problem 68

What is the purpose of applying the (arp) II (dhcpv6) filter?

Check back soon!

Problem 69

List a filter to remove all occurrences of STP or EIGRP.

Check back soon!

Problem 70

List a filter to remove all occurrences of ARP or ICMP.

Check back soon!

Problem 71

List a filter that can be used to display only data packets containing the IP address 208.76.11.230?

Check back soon!
02:07

Problem 72

Use the Wireshark protocol analyzer to capture a file transfer to a TFTP server. Prepare a report on your findings. Identify the port used to establish the TFTP transfer and the source and destination ports used for the TFTP file transfer.

Akash M
Akash M
Numerade Educator

Problem 73

Repeat problem 72 for loading a file from a TFTP server.

Check back soon!

Problem 74

Open the sample wireless capture. Cap file provided in the Chapter 6 Wire- shark folder in the textbook CD. Search for the 74.125.239.27 IP address. Describe what is happening at this address.

Check back soon!

Problem 75

When issuing a command on a server, there are a lot of TCP state of SYN-RECEIVED and ESTABLISHED showing. Should there be any concerns with what netstat is reporting?

Check back soon!