What is a key difference between capture filters and display filters in Wireshark?
Capture filters only work on Wi-Fi; display filters work on Ethernet
b) Capture filters limit packets before recording (smaller files); display filters refine after capture (no data loss)
Display filters require promiscuous mode; capture filters do not
Capture filters show hex data; display filters show protocol trees
This question is part of this quiz :
Wireshark - Packet Capturing and Analyzing