
GIAC Battlefield Forensics and Acquisition
Domain 5Objective 1
Data on the Network GBFA Practice Questions (Page 8)
Part of the Network and Evidence Handling domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 36–40
- 36
A forensic investigator is asked to capture network traffic from a public Wi-Fi network to investigate a cybercrime. The investigator does not have a warrant but has the network administrator's permission. Which action is most appropriate?
Select an answer first - 37
A forensic examiner has completed a network capture and needs to document the evidence for legal proceedings. What is the minimum documentation required to establish a proper chain of custody?
Select an answer first - 38
An examiner is analyzing a packet capture and sees a TCP connection that uses a sequence of packets with the PSH flag set. The data in the packets appears to be fragmented across multiple segments. What is the most likely reason for the PSH flag being set?
Select an answer first - 39
Which of the following is an ethical consideration when handling network evidence?
Select an answer first - 40
In a pcap, you observe a large number of ICMP Echo Request packets sent to a broadcast address, with the source IP spoofed to a victim's address. What is the most likely purpose of this traffic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GBFA” is a trademark of its owner, used for identification only.