Week 17 · reflection

Week 17 Reflection: What Does a Packet Capture Actually Prove?

Use your ARP/Wireshark analyst summary.

Write 150 to 250 words, or record an equivalent explanation, responding to this prompt:

Why is seeing an unfamiliar packet or protocol not enough to classify traffic as malicious?

Include:

  • one normal ARP purpose
  • one exact packet field you used
  • one display filter
  • one conclusion the capture supports
  • one conclusion it does not support
  • one way the topology helped interpret the capture

Finish with:

I would call traffic suspicious only after ________, not simply because ________.