Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 3Objective 2

Application Protocol Analytics GCDA Practice Questions (Page 5)

Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 21–25

  1. 21application · medium

    An analyst is investigating a potential data exfiltration incident. The analyst has identified a series of HTTP POST requests from an internal server to an external IP. Each POST contains a small payload that appears to be base64-encoded. The analyst wants to correlate this activity with a specific asset and determine if it is malicious. Which approach would be most effective?

    Select an answer first
  2. 22application · medium

    You need to detect malware that uses HTTPS to communicate with a C2 server. Your organization has a TLS inspection proxy that can decrypt outbound traffic. What is the most effective detection approach?

    Select an answer first
  3. 23foundation · easy

    An analyst sees an HTTP request with a URI containing '..%2f..%2fetc%2fpasswd'. Which type of application protocol anomaly does this represent?

    Select an answer first
  4. 24application · medium

    You see a series of HTTP requests to a web server with the same URI but with varying query parameters that include base64-encoded strings. The requests are coming from a single internal IP at a rate of one per second. What is the most likely explanation?

    Select an answer first
  5. 25application · medium

    An analyst is examining a packet capture and finds a TCP stream on port 25. The payload contains the string 'EHLO' followed by a server response that includes '250-AUTH LOGIN PLAIN'. The analyst wants to extract the authentication method used by the client. What should the analyst look for in the subsequent packets?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.