You must capture traffic on a Windows Server 2022 Core host and later analyze SMB 3.1.1 and TLS 1.3 handshakes with up-to-date protocol decoders. Which toolset should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Capture with tshark/dumpcap on the server and analyze the pcapng in Wireshark on your workstation..
Why this is the answer
The correct approach is to capture traffic using tshark or dumpcap on the Server Core host and then analyze the resulting .pcapng file with Wireshark on a workstation. Wireshark is the industry standard for network protocol analysis, offering comprehensive and up-to-date decoders for protocols like SMB 3.1.1 and TLS 1.3. tshark and dumpcap are command-line tools that are part of the Wireshark suite and are suitable for capturing on a Server Core installation. Microsoft Network Monitor 3.4 is an outdated tool and does not fully support modern protocols like SMB 3.1.1 and TLS 1.3. Microsoft Message Analyzer was intended as a replacement for Network Monitor but has also been deprecated and is no longer supported. NMCap is a command-line capture tool associated with Network Monitor and suffers from the same limitations regarding modern protocol parsing. Analyzing directly on Server Core with a graphical tool like Wireshark is not feasible, and command-line tools like tshark are primarily for capture, not comprehensive graphical analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed