Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 3Objective 2

Application Protocol Analytics GCDA Practice Questions (Page 3)

Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 11–15

  1. 11application · medium

    A detection analyst observes a host on the internal network sending a large volume of TCP traffic to an external IP on port 53. The payloads are not standard DNS queries; they contain binary data and the transaction IDs are sequential. The analyst needs to determine whether this is a DNS-based data exfiltration attempt. Which combination of evidence would most strongly support that conclusion?

    Select an answer first
  2. 12foundation · easy

    An analyst sees a server sending a large volume of SYN packets to many different hosts without receiving any responses. Which protocol behavior anomaly is most likely indicated?

    Select an answer first
  3. 13application · medium

    While analyzing HTTP traffic, you see a request with a URI of '/upload.php' and a POST body containing a file with the name 'shell.php' and a content-type of 'application/x-php'. The server is a known file upload service. What should you flag?

    Select an answer first
  4. 14application · medium

    An analyst is investigating a malware infection on a workstation. The analyst has a packet capture of the workstation's outbound traffic and wants to identify the malicious domain that the malware is communicating with. The traffic is HTTP, and the analyst has extracted the URI and User-Agent from the requests. Which additional metadata from the HTTP traffic would be most useful to identify the domain?

    Select an answer first
  5. 15foundation · easy

    A security analyst sees SMB traffic on the network and wants to identify which asset is acting as a file server. Which information would best help correlate the SMB activity to a specific asset?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.