Now it's time to check your knowledge. Select the best response and then check your answers, which can be found in the Assessment:
- A significant improvement since moving from GTK to Qt is that Wireshark provides a native interface for macOS that doesn't require the use of _____.
- MATE
- X11
- Transum
- Capinfos
- _____is a capture engine originally developed for Unix-like OS, and is baked into Snort, TCPDUMP, and other packet analyzers to grab packets as they come off the network interface.
- capinfos
- Mate
- libpcap
- Transum
- _____ is a lightweight CLI tool that is not as resource intensive.
- TShark
- mergecap
- dftest
- androiddump
- This program will identify and print a packet's geolocation by using an IPv4 and IPv6 addresses.
- dftest
- TShark
- mergecap
- mmdbresolve
- This is the newest capture engine option for Wireshark, with many benefits and features to enhance your packet capture:
- AirPcap
- NpCap
- WinPcap
- libpcap