Skip to content
CBT Nuggets

Wireshark Certified Analyst (WCA-101) Online Training

Master the core skills of packet analysis that set you apart as a Wireshark Certified Analyst. This Wireshark tutorial shows you how to use the world’s most popular packet capture tool to inspect traffic in motion, identify key protocol headers, and pinpoint issues with dynamic filters. Study with unlimited virtual labs built by IT pros, and build the hands-on experience you need to pass the WCA-101 exam. Earn your Wireshark Certified Analyst credential as you capture real traffic and troubleshoot Ethernet, IP, TCP, and application-layer problems.

Updated November 2025

33Skills
238Videos
6Virtual Labs
35h 25mTotal
238 videos6 labs35h 25m

Who This Course Is For

This course is great for network administrators, IT support specialists, cybersecurity analysts, and ethical hackers who want hands-on packet analysis skills. It’s also great for students and entry-level techs who want to better understand how networks really work.

Skills Your Team Will Gain

  • [
  • 'Capture and analyze real network traffic using Wireshark',
  • 'Apply capture and display filters to isolate relevant packets',
  • 'Identify and interpret Ethernet, IP, TCP, and UDP headers',
  • 'Troubleshoot network issues using Wireshark protocol analysis tools',
  • 'Manage and export Wireshark capture files and objects',
  • 'Use command-line tools for automated packet capture and analysis'
  • ]

Course Curriculum

  • Premium skill.Managing Wireshark Files1h 1m
  • Premium skill.Exporting Objects and Finding Packets52m
  • Premium skill.Core Wireshark Features for Packet Analysis59m
  • Premium skill.Additional Wireshark Features for Packet Analysis1h 1m
  • Premium skill.Wireshark Capture Techniques and Management1h 2m
  • Premium skill.Command-Line and File Operations in Wireshark1h 4m
  • Premium skill.Using Capture and Display Filters51m
  • Premium skill.Membership Filters and Operators55m
  • Premium skill.Mastering Display Filters in Wireshark1h
  • Premium skill.Wireshark Interface and Profiles49m
  • Premium skill.Custom Views and Highlighting for Packet Analysis1h 3m
  • Premium skill.Analyze Ethernet Frames1h 25m
  • Premium skill.Analyze ARP in Action1h 4m
  • Premium skill.Analyzing Attacks at L2 with Wireshark1h 10m
  • Premium skill.IPv4 Header Fundamentals1h 10m
  • Premium skill.IPv4 Fragmentation - Reassembly59m
  • Premium skill.Using IPv4 TTL and Protocol Fields1h 24m
  • Premium skill.IPv4 Troubleshooting With Wireshark1h 5m
  • Premium skill.ICMPv4 Packet Analysis1h
  • Premium skill.Analyzing IPv6 in Wireshark54m
  • Premium skill.UDP Packet Analysis 58m
  • Premium skill.DHCPv4 Packet Analysis1h 18m
  • Premium skill.DNS Packet Analysis1h 13m
  • Premium skill.TCP and the 3-Way Handshake45m
  • Premium skill.TCP SEQ & ACK Numbers 1h 4m
  • Premium skill.TCP Session Teardown and Reset 60m
  • Premium skill.TCP Selective Acknowledgements57m
  • Premium skill.Analyzing TCP MSS 1h 14m
  • Premium skill.TCP Window Scaling and Timing1h 14m
  • Premium skill.Visualizing Traffic with I/O Graphs1h 7m
  • Premium skill.Using Wireshark Flow Graphs1h 14m
  • Premium skill.Using TCP Stream Graphs1h 4m
  • Premium skill.Wireshark Used for Troubleshooting1h 32m

Certification

Wireshark Certified Analyst (WCA-101)

The Wireshark Certified Analyst (WCA-101) certification validates an individual's ability to analyze network traffic using Wireshark, a leading network protocol analyzer. This certification is ideal for network administrators, security analysts, and ...

Exam WCA-101Level ProfessionalDifficulty IntermediateCost $349
network analysisprotocol analysistroubleshootingWireshark proficiencynetwork security
Official certification page

For IT leaders

What IT leaders need to know before assigning this course

Network outages and suspected security events often stall when teams lack a shared packet-analysis process. This intermediate WCA-101 training helps IT Directors standardize how network, infrastructure, support, and security practitioners use Wireshark to capture traffic, manage trace files, apply filters, analyze core protocols, and troubleshoot at Layers 2–4. The course is a meaningful time investment: roughly 35.5 hours per learner, best assigned over several weeks with time to compare packet captures and align internal troubleshooting notes. For change management, Team Leads can use the course to establish common Wireshark profiles, filtering practices, and escalation language so packet evidence is easier to share across teams. CBT Nuggets Playlists can organize the course by role or rollout phase, and Team Reporting helps Training Managers track progress toward WCA-101 readiness.

Team Impact

How this training helps your team succeed

IT teams complete this training to make packet captures more useful during real incidents, not just lab exercises. The course covers Wireshark file handling, object exports, capture and display filters, interface profiles, Ethernet and ARP analysis, IPv4/IPv6, ICMP, UDP, DHCP, DNS, TCP behavior, and troubleshooting graphs.

  • Reduce troubleshooting time by using display filters, membership filters, operators, and custom views to isolate relevant traffic.
  • Improve outage response by analyzing TCP handshakes, resets, acknowledgements, MSS, window scaling, and timing.
  • Strengthen security investigations by recognizing Layer 2 attack patterns, ARP behavior, and abnormal Ethernet-frame activity.
  • Build better network evidence by managing capture files, exporting objects, finding packets, and using I/O, flow, and TCP stream graphs for escalation.

After completion

Knowledge & ability your team will gain

Knowledge

  • Wireshark file management, object export, packet search, profiles, and interface customization.
  • Capture techniques, command-line operations, and capture/display filter logic.
  • Ethernet frames, ARP behavior, Layer 2 attack indicators, and IPv4 header fields.
  • IPv4 fragmentation, TTL, protocol fields, ICMPv4, and IPv6 packet analysis.
  • UDP, DHCPv4, DNS, and TCP session behavior, including setup, teardown, resets, SACK, MSS, and window scaling.

Ability

  • Capture and manage packet data in a repeatable way for troubleshooting and analysis.
  • Build filters that narrow large captures to the traffic that matters.
  • Interpret packet-level evidence across Ethernet, ARP, IP, ICMP, UDP, DNS, DHCP, and TCP.
  • Use I/O graphs, flow graphs, and TCP stream graphs to visualize traffic patterns.
  • Apply Wireshark findings to real troubleshooting workflows and WCA-101 certification preparation.

This course is included with every subscription

Get your team access to all 559 courses, virtual labs, and practice exams.

Most Popular

Team

$749per seat / year

5+ learner seats

Get Started

Enterprise

Customannual contracts

Any size

Contact Enterprise Sales
Calculate the ROI of training your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.