🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)38 / 145
Question 38 of 145

An analyst has a PCAP of an HTTP session where a host downloaded a suspicious executable. Using Wireshark, the analyst needs to reconstruct and save the exact binary that was transferred so it can be submitted to a malware sandbox. Which Wireshark action correctly extracts the transferred file from the TCP stream?

Reviewed for accuracy · Report an issueNext question