
GIAC Certified Detection Analyst
Domain 3Objective 2
Application Protocol Analytics GCDA Practice Questions (Page 8)
Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 36–40
- 36
You are correlating network activity with assets. A database server (10.0.0.10) is seen making HTTP requests to an external IP on port 80. The requests contain a User-Agent of 'curl/7.68.0' and a URI of '/download'. What does this suggest?
Select an answer first - 37
When a packet capture tool decodes an HTTP request, which fields are typically shown in the decoded output?
Select an answer first - 38
An analyst is inspecting HTTP traffic and wants to extract the specific resource path requested by a client. Which field in the HTTP request should they examine?
Select an answer first - 39
A network sensor captures a packet with a TCP payload that begins with 'GET /admin?id=1 AND 1=1-- HTTP/1.1'. The destination is an internal web server. Which anomaly does this packet represent?
Select an answer first - 40
You are investigating a suspected web shell on a public-facing IIS server. Which metadata extracted from HTTP traffic would be most useful to confirm the presence of a web shell and identify the attacker's tooling?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.