
GIAC Certified Intrusion Analyst
The GIAC Certified Intrusion Analyst (GCIA) certification validates your ability to detect and analyze threats through network and host activity. It is designed for practitioners responsible for intrusion detection, traffic analysis, and monitoring. Earning GCIA demonstrates hands-on expertise in configuring intrusion detection systems and interpreting network traffic and log files to defend against real-world attacks.
575 practice questions · Updated 2026-07-30
4Domains
15Objectives
137Concepts
575Questions
GCIA Curriculum
Every domain, objective, and concept the GCIA exam measures.
- TCP/IP Model Layers
- Link Layer Functions
- Ethernet Frame Structure
- ARP Operation
- MAC Addressing
- IPv4 Header Fields
- IPv6 Header Fields
- TCP Header Fields
- UDP Header Fields
- Port Numbers
- Encapsulation and Decapsulation
- MTU and Fragmentation
- IP Header Structure
- IPv4 Header Fields
- IPv6 Header Structure
- IPv6 Extension Headers
- Header Comparison IPv4 vs IPv6
- Header Length and Options
- Fragmentation Fields
- Protocol Field and Next Header
- Time-to-Live and Hop Limit
- Header Checksum
- Source and Destination Addressing
- IPv6 Addressing
- IPv6 Address Types
- IPv6 Header Format
- IPv6 Extension Headers
- IPv6 Neighbor Discovery
- IPv6 Stateless Address Autoconfiguration
- IPv6 Transition Mechanisms
- IPv6 Security Considerations
- TCP Header Structure
- TCP Connection Establishment
- TCP Connection Termination
- TCP Sequence and Acknowledgment Numbers
- TCP Flags and Control Bits
- TCP Window and Flow Control
- TCP Retransmission and Reliability
- TCP Congestion Control
- TCP Ports and Sockets
- TCP Options
- TCP State Machine
- TCP vs UDP
- UDP Header Structure
- UDP Characteristics
- ICMP Message Types
- ICMP Error Reporting
- ICMP Query Messages
- UDP and ICMP in Network Analysis
- Network Forensics Fundamentals
- Traffic Capture Techniques
- Packet Analysis
- Flow Analysis
- Protocol Analysis
- Traffic Reconstruction
- Artifact Extraction
- Correlation and Timeline Analysis
- Anonymization and Privacy
- Reporting and Documentation
- SiLK Tool Suite Overview
- SiLK Flow Data Collection
- SiLK Querying with rwfilter
- SiLK Aggregation with rwgroup
- SiLK Statistics with rwstats
- SiLK Counting with rwcount
- SiLK Flow Record Format
- SiLK Packet Data with rwptoflow
- SiLK Visualization with rwipview
- SiLK Python Bindings
- Other Traffic Analysis Tools Overview
- Argus Flow Analysis
- Bro/Zeek Network Monitoring
- tcpdump and Packet Capture
- Wireshark Analysis
- Integrating Multiple Tools
- Tcpdump syntax
- Basic filter primitives
- Directional qualifiers
- Protocol-specific filters
- Logical operators
- Parentheses and precedence
- Packet content matching
- Capture and output options
- Reading and writing capture files
- Practical filter application
- Wireshark Interface Navigation
- Packet Capture Configuration
- Display Filters
- Packet Dissection and Analysis
- Follow Streams
- Statistics and Summary Tools
- Coloring Rules and Packet Marking
- Exporting and Saving Captures
- IDS Fundamentals
- IDS Types
- Detection Methods
- Network Architecture
- IDS Placement
- Traffic Flow Analysis
- Data Sources
- Alerting and Response
- Advanced IDS Concepts
- IDS Rule Structure
- Rule Header Fields
- Rule Options
- Rule Actions
- Rule Syntax and Format
- Rule Categories and Classification
- Rule Tuning and Optimization
- Rule Testing and Validation
- Packet Structure
- Header Analysis
- Payload Inspection
- Packet Crafting
- Checksum Calculation
- Fragmentation and Reassembly
- TCP Session Analysis
- Protocol Encapsulation
- Packet Timing and Ordering
- Traffic Flow Patterns
- Fragmentation Basics
- Fragment Offset and Flags
- Fragmentation Process
- Reassembly Process
- Fragmentation Attacks and Evasion
- Fragmentation in Network Analysis
- HTTP Protocol Analysis
- HTTPS/TLS Analysis
- DNS Protocol Analysis
- SMTP Protocol Analysis
- POP3 and IMAP Analysis
- FTP Protocol Analysis
- Telnet and SSH Analysis
- DHCP Protocol Analysis
- SNMP Protocol Analysis
- Application Protocol Identification
- Application Layer Anomaly Detection
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCIA, so none is invented.