
GIAC Battlefield Forensics and Acquisition
Domain 5Objective 1
Data on the Network GBFA Practice Questions (Page 1)
Part of the Network and Evidence Handling domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 1–5
- 1
In a TCP packet, which field is used to identify the application-layer protocol that should receive the data?
Select an answer first - 2
You are analyzing a pcap from a compromised server. You notice a large volume of outbound DNS queries to a domain that is not on the corporate allowlist. The queries are for subdomains that appear to be hex-encoded. The server is also sending large amounts of data to an external IP on port 443. What is the most likely combined activity?
Select an answer first - 3
A forensic examiner has captured network traffic from a corporate network during an investigation. The capture includes traffic from a personal device belonging to an employee, which was connected to the corporate Wi-Fi. The company's monitoring policy covers corporate devices but not personal devices. The examiner needs to preserve the evidence for potential litigation. What is the best course of action?
Select an answer first - 4
A forensic examiner is preparing to capture network traffic from a corporate switch port that carries a mix of user and server traffic. The organization has a legal requirement to preserve evidence for potential litigation. The examiner needs a capture that preserves the full packet contents and can be used to reconstruct application-layer sessions later. Which approach best meets the requirement?
Select an answer first - 5
During a network traffic analysis, an examiner notices that a server is sending a large number of TCP RST packets to a client immediately after receiving a SYN packet. The client is not sending any additional packets. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.