
GIAC Battlefield Forensics and Acquisition
Domain 5Objective 1
Data on the Network GBFA Practice Questions (Page 6)
Part of the Network and Evidence Handling domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 26–30
- 26
Which protocol is responsible for resolving domain names to IP addresses?
Select an answer first - 27
A network capture has been completed and the examiner needs to transfer the evidence to a forensic lab. The evidence is stored on a portable drive. What is the best practice for transferring the evidence to maintain its integrity?
Select an answer first - 28
While analyzing a pcap, you notice a series of TCP connections to a server on port 22 (SSH). Each connection completes a full handshake, then sends a small amount of data, and then closes with a FIN. The source IPs are all different and appear to be from various countries. What is the most likely explanation?
Select an answer first - 29
Which tool is specifically designed to capture network traffic in promiscuous mode and save it to a file in pcap format for later forensic analysis?
Select an answer first - 30
You are analyzing a pcap and notice a series of HTTP requests to a single URL with varying query parameters, each returning a 404 status. The requests originate from a single IP and occur every 5 seconds. What is the most likely explanation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.