Guide 09 / 09 • Interview + practical learning

Wireshark

20 representative questions, English and Roman Urdu explanations, examples, exercises and original visual diagrams.

Beginner + intermediate4–6 hours daily20 questions

← Pack index and combined learning plan

How to use this guide

Read the short answer first, then explain the example without reading. Complete the practice task and collect evidence. The 50/40/30/20-question counts follow twice the higher estimates in your table; they are a preparation target, not a guaranteed employer question bank.

Pehle short answer parho, phir example apni zubaan mein samjhao. Practice task complete karke evidence rakho. Answers ratta laganay ke bajaye steps aur reasoning samjho.

Lab requirements: Wireshark and appropriate capture permissions, local authorised test traffic or trusted vendor sample captures. Capture only traffic you are authorised to inspect. Preserve sensitive packet data and recognise that capture placement limits visibility.

Course outcomes / Aap kya kar saken ge

Beginner

  • Choose a capture point and recognise its limits
  • Use basic capture and display filters
  • Explain DNS, TCP setup and encryption boundaries

Capture point aur limits samjhao

Capture aur display filters use karo

DNS, TCP aur encryption explain karo

Intermediate

  • Interpret handshake failures and TCP analysis cautiously
  • Correlate packet timing with application and device logs
  • Analyse streams and conversations with scope limitations
  • Preserve capture provenance and write defensible findings

Handshake aur TCP analysis cautiously interpret karo

Packets aur app logs ki timing joro

Streams aur visibility limits analyse karo

Capture preserve aur clear findings likho

Learning path and practice schedule

This is a suggested 68-hour topic plan: 20 beginner hours plus 48 additional intermediate hours. At 4–6 hours a day, allow approximately 4–5 study days for the beginner stage and 12–17 study days total for this guided course. These are planning estimates, not promises of independent workplace competence. Repeat stages if the practical checkpoints are weak. Related subjects overlap in the combined plan.

Daily routine: 4–6 hours

ActivityCore 4 hoursOptional extra 2 hours
Concepts and official tutorial60 minutes—
Hands-on lab or evidence exercise120 minutes90 minutes: a harder case or failed scenario
Interview answers aloud30 minutes30 minutes: mock interview and follow-ups
Review and evidence log30 minutes—

Roman Urdu: Roz aik ghanta concepts, do ghantay practical, aadha ghanta answers bol kar aur aadha ghanta review karo. Extra do ghantay hon to difficult lab aur mock interview karo. Har haftay chhay study days aur aik rest/catch-up day rakho.

Study time means focused work, excluding breaks. Allocate at least half to practical work. If no tenant or lab is available, analyse supplied data and diagrams, but record that limitation and revisit the task when you have access.

Stage and timeDirection and practiceResource / tutorialDeliverable in Roman Urdu
1. Beginner
6 hours
1–2 study days
Capture and visibility
Read capture setup and map interfaces. Use a short authorised local capture or a trusted sample file; record capture context.
Capture setup
Wireshark capture setup
Interface aur capture context record karo.
2. Beginner
8 hours
2–2 study days
Filter and protocol basics
Practise ten display filters and compare them with capture syntax. Identify DNS exchanges and a TCP handshake.
Filter reference and user guide
Display-filter syntax and reference
Das filters aur DNS/TCP exchange explain karo.
3. Beginner
6 hours
1–2 study days
Evidence interpretation
Follow a safe unencrypted stream and inspect an encrypted session. State what content is and is not visible.
Following streams
Following protocol streams
Encrypted aur unencrypted evidence ka farq likho.
4. Intermediate
16 hours
3–4 study days
TCP and DNS diagnosis
Analyse sample resets, no-reply handshakes, DNS errors and retransmissions. Consider capture artefacts and alternative causes.
TCP analysis and user guide
Wireshark TCP analysis
Har sample par observed facts aur alternatives likho.
5. Intermediate
16 hours
3–4 study days
Performance and correlation
Measure exchanges, compare conversations and align time zones with fictional application logs. Explain visibility gaps.
User guide
Wireshark User’s Guide
Timing measurements aur correlation report banao.
6. Intermediate
16 hours
3–4 study days
Capstone and reporting
Investigate a slow-connection sample and write a packet-backed conclusion. Preserve the original file and produce a one-minute interview explanation.
Capture and analysis references
Wireshark capture setup
Capture provenance aur final report complete karo.

Practical exit check

Beginner: Complete a basic task using documentation, explain the result and recognise when to escalate.

Intermediate: Complete a common scenario without a step-by-step answer, justify your checks, test an alternative explanation and verify the result. You may consult references as analysts do at work.

Beginner par documentation ke saath basic task karo. Intermediate par ready-made steps ke baghair scenario solve, reasoning explain aur result verify karo.

Visual explanations

Wireshark concept and evidence mapCapture pointVisible packetsFilters + reassemblyTiming + protocolsEvidence +limitations
Original concept diagram. The three inputs on the left contribute to the central investigation or assessment, supporting the decision on the right. Relationships are conceptual, not a screenshot or an exhaustive deployment architecture.

Left ki information central analysis mein use hoti hai, phir decision ya response support hota hai.

Wireshark troubleshooting decision diagramYes / HaanNo / NahinConnection appears slowInspect DNS + TCPTransport established?Check response timingInvestigate setup failure
Example troubleshooting decision. Use the branch that matches the observed evidence; complete verification after any corrective action.

Evidence ke mutabiq Yes ya No branch choose karo. Action ke baad result verify karo.

20 interview questions

Level labels indicate study focus, not a formal certification standard. Each short answer is a starting point for a 30–60 second response; expand with the example and your own honest experience.

20 questions shown
  1. What is Wireshark?
  2. Capture filter versus display filter: what is the difference?
  3. How do you choose a capture interface?
  4. Why might you see no packets?
  5. How do you filter by IP or port?
  6. What is the TCP three-way handshake?
  7. TCP versus UDP: what is the difference?
  8. How do you investigate DNS problems?
  9. What is a TCP retransmission?
  10. What is a TCP reset?
  11. What is Follow TCP Stream used for?
  12. Can Wireshark read HTTPS content automatically?
  13. How do you investigate a TLS connection failure?
  14. What does Expert Information provide?
  15. What are Conversations and Endpoints views used for?
  16. How do you investigate slow application performance?
  17. What is a SPAN port or network TAP used for?
  18. Why are timestamps and time zones important?
  19. How do you preserve and share a capture?
  20. What can you conclude from packets versus what remains uncertain?
Beginner focus
Question 01 / 20

What is Wireshark?

Short interview answer · English

A packet analyser used to capture and inspect network traffic.

Why this matters · English explanation

It sees traffic available at the chosen capture point, not automatically every packet on a network.

Roman Urdu explanation
Wireshark packets analyse karta hai. Selected capture point par available traffic hi nazar aata hai.
Worked context / illustrative example
A laptop capture shows its own DNS and TCP exchanges.
Your practical task
Explain the visibility limits of your capture point.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Beginner focus
Question 02 / 20

Capture filter versus display filter: what is the difference?

Short interview answer · English

Capture filters limit collected packets; display filters limit the view of already captured packets.

Why this matters · English explanation

Their syntax differs; displayed filtering does not remove packets from the original capture.

Roman Urdu explanation
Capture filter collection limit karta hai; display filter view. Dono ki syntax different hai.
Worked context / illustrative example
Capture filter: tcp port 443. Display filter: tcp.port == 443.
Your practical task
Explain which filter can lose uncaptured evidence.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Display-filter syntax and reference

Beginner focus
Question 03 / 20

How do you choose a capture interface?

Short interview answer · English

Select the interface carrying the relevant traffic and confirm activity and addresses.

Why this matters · English explanation

VPNs, virtual adapters and remote paths can alter visibility.

Roman Urdu explanation
Relevant traffic wala interface choose karo. VPN aur virtual adapters ka effect check karo.
Worked context / illustrative example
A capture on Ethernet misses traffic routed through a VPN adapter.
Your practical task
List checks before starting a short authorised capture.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark capture setup

Beginner focus
Question 04 / 20

Why might you see no packets?

Short interview answer · English

Wrong interface, capture restrictions, inactive traffic, restrictive filters or insufficient permissions.

Why this matters · English explanation

Generate harmless authorised test traffic and simplify filters before drawing conclusions.

Roman Urdu explanation
Interface, permissions aur filters check karo. Safe test traffic se collection verify karo.
Worked context / illustrative example
An overly restrictive capture filter excludes the DNS query being investigated.
Your practical task
Create a no-packets troubleshooting sequence.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark capture setup

Beginner focus
Question 05 / 20

How do you filter by IP or port?

Short interview answer · English

Use valid display-filter fields and operators for the desired source, destination or either direction.

Why this matters · English explanation

Specify the question before choosing a filter.

Roman Urdu explanation
IP aur port filters se relevant packets dekho. Source, destination aur dono directions ka farq samjho.
Worked context / illustrative example
ip.addr == 192.0.2.10 or tcp.port == 443 are separate example display filters.
Your practical task
Compare ip.src with ip.addr.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Display-filter syntax and reference

Beginner focus
Question 06 / 20

What is the TCP three-way handshake?

Short interview answer · English

SYN, SYN-ACK and ACK establish a TCP connection.

Why this matters · English explanation

A handshake establishes transport state, not application authentication or successful business processing.

Roman Urdu explanation
SYN, SYN-ACK aur ACK connection establish kartay hain. Login success is se prove nahin hota.
Worked context / illustrative example
A client sends SYN but no SYN-ACK returns at the capture point.
Your practical task
Draw the exchange and explain a missing reply.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Beginner focus
Question 07 / 20

TCP versus UDP: what is the difference?

Short interview answer · English

TCP provides a reliable ordered byte stream; UDP provides datagrams without those transport guarantees.

Why this matters · English explanation

Applications can implement their own reliability over UDP.

Roman Urdu explanation
TCP reliable ordered stream hai; UDP datagrams. Application apni reliability bhi implement kar sakti hai.
Worked context / illustrative example
DNS often uses UDP but can also use TCP.
Your practical task
Give two application examples without assuming one protocol always wins.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Intermediate focus
Question 08 / 20

How do you investigate DNS problems?

Short interview answer · English

Inspect queries, responses, names, record types, response codes and timing.

Why this matters · English explanation

A visible answer can still be wrong for the intended service.

Roman Urdu explanation
DNS query, answer, record type aur response code dekho. Answer ka correct hona bhi verify karo.
Worked context / illustrative example
A query receives NXDOMAIN for a name that the user expects to exist.
Your practical task
Use the dns display filter and explain the exchange.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Beginner focus
Question 09 / 20

What is a TCP retransmission?

Short interview answer · English

A repeated segment associated with TCP recovery or analysis inference.

Why this matters · English explanation

Loss, delays, capture artefacts and visibility gaps can affect interpretation.

Roman Urdu explanation
Retransmission repeated segment hai. Packet loss ke saath capture issue bhi ho sakta hai.
Worked context / illustrative example
A trace contains retransmission indicators after a delay.
Your practical task
Explain why one retransmission is not enough to locate the fault.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark TCP analysis

Beginner focus
Question 10 / 20

What is a TCP reset?

Short interview answer · English

A segment with the RST flag indicating connection termination or rejection in the observed context.

Why this matters · English explanation

Identify direction and surrounding packets; it does not by itself identify the root cause.

Roman Urdu explanation
RST connection reject ya terminate karne ka signal ho sakta hai. Direction aur context dekho.
Worked context / illustrative example
A SYN receives an immediate reset from the destination.
Your practical task
Compare that pattern with no response.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark TCP analysis

Intermediate focus
Question 11 / 20

What is Follow TCP Stream used for?

Short interview answer · English

Reconstructing a conversation from available captured stream data.

Why this matters · English explanation

Encrypted application content remains encrypted unless appropriate authorised decryption is available.

Roman Urdu explanation
Follow TCP Stream conversation jorta hai. TLS content bina proper decryption ke readable nahin hota.
Worked context / illustrative example
Follow an unencrypted lab HTTP exchange.
Your practical task
Explain missing data and encryption limitations.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Following protocol streams

Intermediate focus
Question 12 / 20

Can Wireshark read HTTPS content automatically?

Short interview answer · English

No; encryption protects application content, although metadata remains visible.

Why this matters · English explanation

Authorised decryption needs suitable secrets and compatible capture conditions.

Roman Urdu explanation
HTTPS content normally encrypted hota hai. Metadata dikhta hai, content ke liye authorised decryption chahiye.
Worked context / illustrative example
A trace shows connection timing but not the protected message body.
Your practical task
List visible metadata and unavailable content.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Intermediate focus
Question 13 / 20

How do you investigate a TLS connection failure?

Short interview answer · English

Review transport setup, TLS handshake messages, available alerts and timing, then correlate application logs.

Why this matters · English explanation

Do not claim a specific certificate or cipher cause without supporting evidence.

Roman Urdu explanation
TCP aur TLS handshake, alerts aur app logs compare karo. Exact cause evidence ke baghair assume mat karo.
Worked context / illustrative example
TCP succeeds but the TLS exchange ends before application data.
Your practical task
Separate transport success from TLS and application success.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Intermediate focus
Question 14 / 20

What does Expert Information provide?

Short interview answer · English

Analysis hints about notable packet conditions.

Why this matters · English explanation

Warnings are starting points and may reflect capture limitations rather than actual network faults.

Roman Urdu explanation
Expert Information clues deti hai. Warning ko final root cause mat samjho.
Worked context / illustrative example
A warning appears in a capture that began halfway through a connection.
Your practical task
Explain how you would corroborate the warning.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Intermediate focus
Question 15 / 20

What are Conversations and Endpoints views used for?

Short interview answer · English

Summarising communicating peers and traffic statistics.

Why this matters · English explanation

High volume or an unfamiliar peer needs context before being labelled exfiltration.

Roman Urdu explanation
Conversations peers aur traffic summary dikhata hai. Zyada traffic hamesha data theft nahin.
Worked context / illustrative example
A scheduled backup produces the largest transfer.
Your practical task
Identify a suspicious hypothesis and a legitimate explanation.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Intermediate focus
Question 16 / 20

How do you investigate slow application performance?

Short interview answer · English

Compare DNS, connection setup, retransmissions, response timing and application evidence.

Why this matters · English explanation

A single capture point may not reveal where delay originates.

Roman Urdu explanation
DNS, TCP aur response timings compare karo. Aik capture point se delay ki exact jagah hamesha nahin milti.
Worked context / illustrative example
Fast connection setup is followed by a long wait for a server response.
Your practical task
Write a measured conclusion and next diagnostic step.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark TCP analysis

Intermediate focus
Question 17 / 20

What is a SPAN port or network TAP used for?

Short interview answer · English

Providing visibility into traffic beyond the local endpoint at an authorised capture point.

Why this matters · English explanation

Mirroring capacity, direction and packet loss affect evidence completeness.

Roman Urdu explanation
SPAN ya TAP wider traffic capture ke liye hota hai. Mirror limitations aur packet loss check karo.
Worked context / illustrative example
A switch mirror provides a server segment's traffic to an analysis interface.
Your practical task
Define authorised scope and completeness checks.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark capture setup

Intermediate focus
Question 18 / 20

Why are timestamps and time zones important?

Short interview answer · English

They align packet evidence with device and application logs.

Why this matters · English explanation

Different clocks or display settings can create a false event sequence.

Roman Urdu explanation
Packet aur app logs ki timing align karo. Time zone difference false sequence bana sakta hai.
Worked context / illustrative example
A trace displays local time while a server log records UTC.
Your practical task
Convert two fictional timestamps and document the basis.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Intermediate focus
Question 19 / 20

How do you preserve and share a capture?

Short interview answer · English

Keep the original, record capture context and use controlled copies with appropriate access.

Why this matters · English explanation

Packet files can contain sensitive information; sanitisation must preserve investigative meaning.

Roman Urdu explanation
Original capture preserve aur context record karo. Sharing access controlled rakho.
Worked context / illustrative example
A limited capture excerpt is shared while the original remains protected.
Your practical task
Write a capture provenance and handling note.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark capture setup

Intermediate focus
Question 20 / 20

What can you conclude from packets versus what remains uncertain?

Short interview answer · English

State observed exchanges, failures and timing separately from hypotheses about cause or intent.

Why this matters · English explanation

Use additional capture points or logs where the evidence is incomplete.

Roman Urdu explanation
Observed packets ko facts aur cause ko hypothesis ke taur par clear rakho. Missing evidence explain karo.
Worked context / illustrative example
Repeated SYNs without replies show no reply at this capture point, not proof that a firewall caused it.
Your practical task
Deliver a one-minute evidence-based packet-analysis summary.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Wireshark User’s Guide

Quick revision sheet

Cover the answers and explain each question aloud. For scenarios use: Trigger → Evidence → Checks → Decision → Verification → Documentation.

Scenario answer mein trigger, evidence, checks, decision, verification aur documentation clear batao.

QuestionAnswer prompt
1. What is Wireshark?A packet analyser used to capture and inspect network traffic.
2. Capture filter versus display filter: what is the difference?Capture filters limit collected packets; display filters limit the view of already captured packets.
3. How do you choose a capture interface?Select the interface carrying the relevant traffic and confirm activity and addresses.
4. Why might you see no packets?Wrong interface, capture restrictions, inactive traffic, restrictive filters or insufficient permissions.
5. How do you filter by IP or port?Use valid display-filter fields and operators for the desired source, destination or either direction.
6. What is the TCP three-way handshake?SYN, SYN-ACK and ACK establish a TCP connection.
7. TCP versus UDP: what is the difference?TCP provides a reliable ordered byte stream; UDP provides datagrams without those transport guarantees.
8. How do you investigate DNS problems?Inspect queries, responses, names, record types, response codes and timing.
9. What is a TCP retransmission?A repeated segment associated with TCP recovery or analysis inference.
10. What is a TCP reset?A segment with the RST flag indicating connection termination or rejection in the observed context.
11. What is Follow TCP Stream used for?Reconstructing a conversation from available captured stream data.
12. Can Wireshark read HTTPS content automatically?No; encryption protects application content, although metadata remains visible.
13. How do you investigate a TLS connection failure?Review transport setup, TLS handshake messages, available alerts and timing, then correlate application logs.
14. What does Expert Information provide?Analysis hints about notable packet conditions.
15. What are Conversations and Endpoints views used for?Summarising communicating peers and traffic statistics.
16. How do you investigate slow application performance?Compare DNS, connection setup, retransmissions, response timing and application evidence.
17. What is a SPAN port or network TAP used for?Providing visibility into traffic beyond the local endpoint at an authorised capture point.
18. Why are timestamps and time zones important?They align packet evidence with device and application logs.
19. How do you preserve and share a capture?Keep the original, record capture context and use controlled copies with appropriate access.
20. What can you conclude from packets versus what remains uncertain?State observed exchanges, failures and timing separately from hypotheses about cause or intent.

Capstone and assessment

Analyse a sample connection failure or slow exchange. Submit filters, packet references, timing measurements, plausible causes and the next evidence needed; do not claim a firewall cause from missing replies alone.

Capstone mein evidence, reasoning aur verified result do. Jo cheez available nahin us ki limitation likho. Lab work ko production experience keh kar present mat karo.

AreaSelf-assessment target
Evidence and technical accuracyAll key claims supported by relevant records, outputs or diagrams
Investigation reasoningAt least one alternative explanation tested; gaps clearly identified
Practical deliveryTask outcome verified, including one negative or failure test
CommunicationExplain the case in two minutes and answer two unprepared follow-ups

This is a study assessment, not a vendor certification or guarantee of interview success. Repeat the task if you cannot explain why your checks were necessary.

Official references and tutorials

References provide deeper detail. Some pages are broad documentation hubs: navigate to the relevant feature and check current licensing, platform support and permissions. Guidance is paraphrased; diagrams and fictional examples are original study material.