Sign Up
Log In
Home
discussion
Exam 200-201 Question id=6021 Network intrusion analysis

Refer to the exhibit.

- Internet Protocol version 4, Src: 192.168.122.100 (192.168.122.100), Dst: 81.179.179.69 (81.179.179.69) version: 4 Header Length: 20 bytes + Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT(Not ECN-Capable Transport)) Total Length: 538 Identification: Ox6bse (27534) + Flags: 0x02 (Don’t Fragment) Fragment offset: 0 Time to live: 128 Protocol: TCP (6) + Header checksum: 0x000 [Validation disabled] Source: 192.168.122.100 (192.168.122.100) Destination: 81.179.179.69 (81.179.179.69) [Source GeoIP: Unknown] + Transmission control protocol. src port: 50272 (50272) Dst Port: 80 (80). Seq: 419451624. Ack: 970444123. Len: 490 [Source GeoIP: Unknown]

What should be interpreted from this packet capture?

A. 81.179.179.69 is sending a packet from port 80 to port 50272 of IP address 192.168.122.100 using UDP protocol.
B. 192.168.122.100 is sending a packet from port 50272 to port 80 of IP address 81.179.179.69 using TCP protocol.
C. 192.168.122.100 is sending a packet from port 80 to port 50272 of IP address 81.179.179.69 using UDP protocol.
D. 81.179.179.69 is sending a packet from port 50272 to port 80 of IP address 192.168.122.100 using TCP UDP protocol.