← Network Forensics — PCAP Analysis, Protocol Dissection, and C2 Extraction
Module Quiz
10 questions · Pass at 80%
Question 1 of 10
An analyst needs to extract all DNS query names from a 20 GB PCAP without loading it into Wireshark's GUI. Which tshark command accomplishes this?