What is Wireshark used for?
- A.Writing firewall rules
- B.Encrypting network communications; Wireshark blocks malicious packets as it captures them
- C.Scanning for malware on endpoints; sandboxing runs untrusted code with full administrative rights
- D.Capturing and analyzing network packets in real-time
Why D is correct
Wireshark is an open-source packet analyzer (sniffer) that captures network traffic and displays it in a human-readable format. Security analysts use it to troubleshoot network issues, analyze suspicious traffic, investigate security incidents, and verify that encryption is working properly.
Know someone studying for Security Fundamentals? Send them this one.