SOC Interview: I Ask Candidates This One Wireshark Question (Wireshark Walkthrough)

In SOC interviews, candidates are often shown a single packet and asked a deceptively simple question: “Where did this actually go?” Most people start talking about HTTP. Ports. TCP flags. Very few talk about the Ethernet frame. And that’s usually where the interview ends. In this video, we use a real training capture to break down: Identifying the true sender at Layer 2 Mapping Ethernet destination to actual devices Understanding EtherType and protocol layering Calculating byte offsets for payload validation Analyzing ARP request and reply behavior Thinking like a SOC analyst instead of memorizing filters If you're preparing for a SOC role, this is the depth interviewers look for. 📦 Download the Free PCAP (SOC5) Work through this capture yourself and follow along step-by-step: 👉 Download SOC5 here: https://dr-k-cybersecurity.kit.com/3e... Open it in Wireshark and practice — don’t just watch. 🎓 Structured, Hands-On Wireshark Training If you want deeper, real-world packet analysis practice beyond YouTube walkthroughs: 👉 Wireshark Ultimate Hands-On Course: https://trk.udemy.com/kOn1QV?u=https:... This course focuses on investigation mindset and real analyst reasoning — not memorizing lab answers. ⚠️ Affiliate Disclosure Some of the links in this description are affiliate links. If you choose to purchase through them, I may earn a commission at no additional cost to you. It helps support the channel and allows me to continue creating hands-on cybersecurity training content. 🔎 Topics Covered Ethernet II header analysis MAC address attribution EtherType 0x0800 and 0x0806 ARP opcode structure Byte offset analysis in Wireshark Layered protocol reasoning SOC interview preparation If this helped you think more clearly about packet analysis, consider subscribing. There’s a big difference between using Wireshark and understanding traffic — and interviews absolutely test that difference.