Review of the Wireshark Certified Network Analyst Certification

The Wireshark Certification Program strives to test a candidate’s knowledge and ability to troubleshoot, optimize and secure a network based on evidence found by analyzing traffic captured with the world’s most popular and widely-deployed analyzer, Wireshark. 

Having completed the WCNA certification exam recently, I thought it would be worth writing about for others that might consider studying for it. If  you have listened to the Packet Pushers Podcast Show 108 with Gerald Combs, you know something about the WCNA program already. To obtain the WCNA certification you need to pass a single written exam.

The WCNA prerequisites and materials that can be used are listed below:

  • Basic knowledge of networking;
  • Wireshark Certified Network Analyst Study guide;
  • Wireshark Certified Network Analyst Exam prep guide;
  • Online courses;
  • Instructor-led courses;
  • Self-paced courses;
  • Experience with Wireshark.

All of these materials can be found at the Wireshark University site. I ordered both the study and exam preparation guides. The exam prep guide ships with a CD-ROM containing practice questions.

Is it worth ordering these books and studying for the WCNA certification?

If you ask me, it is definitely worth it. After all, it makes you a better engineer. The following topics are covered.

  • Depending on your knowledge level, the books will be easy to go through. You will learn basic and advanced usage of Wireshark. For example, from one graph that you can pull out of a 20K packet dump, you can learn how to spot window size problems. Learning how to use advanced I/O graphs and spotting QoS issues makes life a lot easier.
  • The materials come with example trace files that are also used in the book. This is a very good way for you to learn Wireshark.
  • What is the best place in the network to place the network analyzer?
  • If you have some protocol knowledge (ARP, FTP, SMTP, POP3, HTTP, DHCP, etc.), you can easily go through some chapters. Even if you think you know these protocols, it is worth going through the materials.
  • You learn basic and advanced TCP protocol usage. For example, what happens when TCP synchronizes? Or, what TCP options will be used if different values between both endhosts are “advertised”?
  • The book contains real-life examples of troubleshooting issues and how they eventually were resolved – a nice read.
  • How to work with the Wireshark display, capture filters, coloring traffic, and marking/deleting packets, plus how to decrypt SSL traffic and RADIUS.
  • Analyzing VoIP and wireless performance.
  • How to detect security-related events from well-known attacks that are floating around the internet.

These are some example questions I had before I started studying:

  • How would you handle a problem that happens only once every 24 hours?
  • What external tools are available for Wireshark, and what can they be used for?
  • What’s the best way to find “the gem” buried in about 400.000 of packets in your trace files?
  • How do you deal with high traffic environments?
  • How do protocol dissectors work?

Some, if not all, of these got answered.

What do you get after obtaining the WCNA credentials?

  • You will get a nice booklet with information about the WCNA and your WCNA certification number.
  • User credentials for the WCNA portal (http://www.wcnaportal.com). The WCNA portal has some cool quizzes and lecture about RFC’s. Using these quizzes and videos, you can earn CPE credits.
  • You need to earn 20 CPE credits a year to maintain the credentials.
  • A few Wireshark laptop stickers, which is great stuff.

If you need more information about the WCNA program, you can visit the Wireshark University.

Wouter Prins
WCNA #352967

About Wouter Prins

Wouter Prins is a senior network engineer with a focus on enterprise- and ISP environments and working for a dutch network integrator. He is CCIE #25628 and works with Cisco, Brocade, Juniper, Extreme, Alcatel-Lucent and xWDM vendors. In his spare time he likes powerkiting and gaming. You can find Wouter on LinkedIn or follow @wouterprins on Twitter.

  • Hoodbu

    Thanks for the post. How much does the exam cost?

    • Wouter Prins

      Hi Hoodbu, the costs of the exam are 299$ USD

  • Techkid

    Ive already purchased the wireshark book. Im planning to take this exam when im done with my CCNP. Wireshark has helped me to solve a lot of problems at work and is surely worth investing in. thanks for the post

    • Wouter Prins

      Yeah, it’s a must have tool in some situations. :) Good luck on your CCNP and WCNA studies!

  • http://twitter.com/networkdongle garry baker

    Did you try the practice exam for 29usd, or just go straight for the 299usd real test?

    • Wouter Prins

      Yeah, i took the small test as well. Just to check on the format and level of questions. Some questions were the same as in the exam prep guide though :)

      • Laura Chappell

        Actually the questions are NOT the same… though it may feel like it at times. There are changes in the stem or distractors or images in all the practice questions.

  • http://www.packetu.com/ Paul Stewart

    The Wireshark Book is Awesome. I’m sure Laura’s classes are as well. I took the WCNA about 20 months ago. Actually found it a little easier than expected. Only really disagreed with one question (due to it being subjective to thinking about a rarely unused, at least not intentionally used, feature).

    • http://twitter.com/networkdongle garry baker

      looks like there is a 2nd edition out now with update IPv6 and SSL analysis…
      Wonder if anyone has read the Kindle version, we had the book at my old job it was a work copy, i just wonder if the Kindle formatting is decent or not?

      • http://www.packetu.com/ Paul Stewart

        If you send @laurachappell a message on twitter, she’ll probably be truthful about it. I think one of the original concerns with version one was formatting. As far as I know, it never got a Kindle edition. If that is the case, they probably either overcame that, or they’re just getting a lot of pressure.

        You know, I love this one in an actual book. I found myself flipping back and forth, so the hard copy just worked. It’d be nice to have it all portable and electronic too though.

      • Laura Chappell

        Hi Garry…

        The Kindle version contains EXACTLY what is in the hardcopy. The biggest difference is the weight (grin) and we had to pull out all the tables and reformat them for the Kindle.

        The Kindle version is nice because it is in color – and you may know I am a firm believer in using color so Wireshark SCREAMS at you when there is a problem.

        Hope that helps you out.

  • Laura Chappell

    Wouter,

    Thanks for your thoughts on the WCNA program and exam. I’ll try to keep an eye out over here in case there are questions that I can answer, but it sounds like you have it covered.

    • Wouter Prins

      Laura, that would be a great addition! :)

  • http://twitter.com/insektazz insekt

    Hi,
    thanks for this note.
    How many days you spent for preparation to exam?

    • Wouter Prins

      I’ve spent a few days going through the books, doing exercises in wireshark, reading wireshark mailinglists, wiki’s. It’s hard to say “x days” because it depends on your current knowledge of networking and experience with wireshark.

  • Charlotte Rawlings

    Wow, definitely going to do the Wireshark Certified Network Analyst Certification after I have completed my CCNA. Already have the CompTIA Network+.

  • layer4down

    Hi Wouter,

    Thanks for the write-up here, I felt this was a fair reflection of the material. I earned my WCNA back in early 2011, just before earning my CCNP R/S as well. For where I was knowledge-wise, I definitely felt that this was a good test reflecting the content which was instructed. I gained A LOT of technical knowledge and understanding from the book and feel it’s a good reference to have all around. I would definitely recommend this certification to systems and network engineers alike and look forward to future certifications offered by this vendor.