Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Certified Intrusion Analyst

GCIA

The GIAC Certified Intrusion Analyst (GCIA) certification validates your ability to detect and analyze threats through network and host activity. It is designed for practitioners responsible for intrusion detection, traffic analysis, and monitoring. Earning GCIA demonstrates hands-on expertise in configuring intrusion detection systems and interpreting network traffic and log files to defend against real-world attacks.

575 practice questions · Updated 2026-07-30

4Domains
15Objectives
137Concepts
575Questions

GCIA Curriculum

Every domain, objective, and concept the GCIA exam measures.

IP Headers

11 concepts · 42 questions
  1. IP Header Structure
  2. IPv4 Header Fields
  3. IPv6 Header Structure
  4. IPv6 Extension Headers
  5. Header Comparison IPv4 vs IPv6
  6. Header Length and Options
  7. Fragmentation Fields
  8. Protocol Field and Next Header
  9. Time-to-Live and Hop Limit
  10. Header Checksum
  11. Source and Destination Addressing

IPv6

8 concepts · 36 questions
  1. IPv6 Addressing
  2. IPv6 Address Types
  3. IPv6 Header Format
  4. IPv6 Extension Headers
  5. IPv6 Neighbor Discovery
  6. IPv6 Stateless Address Autoconfiguration
  7. IPv6 Transition Mechanisms
  8. IPv6 Security Considerations

TCP

12 concepts · 50 questions
  1. TCP Header Structure
  2. TCP Connection Establishment
  3. TCP Connection Termination
  4. TCP Sequence and Acknowledgment Numbers
  5. TCP Flags and Control Bits
  6. TCP Window and Flow Control
  7. TCP Retransmission and Reliability
  8. TCP Congestion Control
  9. TCP Ports and Sockets
  10. TCP Options
  11. TCP State Machine
  12. TCP vs UDP

UDP and ICMP

6 concepts · 33 questions
  1. UDP Header Structure
  2. UDP Characteristics
  3. ICMP Message Types
  4. ICMP Error Reporting
  5. ICMP Query Messages
  6. UDP and ICMP in Network Analysis

Network Forensics and Traffic Analysis

10 concepts · 47 questions
  1. Network Forensics Fundamentals
  2. Traffic Capture Techniques
  3. Packet Analysis
  4. Flow Analysis
  5. Protocol Analysis
  6. Traffic Reconstruction
  7. Artifact Extraction
  8. Correlation and Timeline Analysis
  9. Anonymization and Privacy
  10. Reporting and Documentation

SiLK and Other Traffic Analysis Tools

16 concepts · 49 questions
  1. SiLK Tool Suite Overview
  2. SiLK Flow Data Collection
  3. SiLK Querying with rwfilter
  4. SiLK Aggregation with rwgroup
  5. SiLK Statistics with rwstats
  6. SiLK Counting with rwcount
  7. SiLK Flow Record Format
  8. SiLK Packet Data with rwptoflow
  9. SiLK Visualization with rwipview
  10. SiLK Python Bindings
  11. Other Traffic Analysis Tools Overview
  12. Argus Flow Analysis
  13. Bro/Zeek Network Monitoring
  14. tcpdump and Packet Capture
  15. Wireshark Analysis
  16. Integrating Multiple Tools

Tcpdump Filters

10 concepts · 20 questions
  1. Tcpdump syntax
  2. Basic filter primitives
  3. Directional qualifiers
  4. Protocol-specific filters
  5. Logical operators
  6. Parentheses and precedence
  7. Packet content matching
  8. Capture and output options
  9. Reading and writing capture files
  10. Practical filter application

Wireshark Fundamentals

8 concepts · 38 questions
  1. Wireshark Interface Navigation
  2. Packet Capture Configuration
  3. Display Filters
  4. Packet Dissection and Analysis
  5. Follow Streams
  6. Statistics and Summary Tools
  7. Coloring Rules and Packet Marking
  8. Exporting and Saving Captures

  1. IDS Fundamentals
  2. IDS Types
  3. Detection Methods
  4. Network Architecture
  5. IDS Placement
  6. Traffic Flow Analysis
  7. Data Sources
  8. Alerting and Response

Advanced IDS Concepts

1 concepts · 26 questions
  1. Advanced IDS Concepts

Intrusion Detection System Rules

8 concepts · 38 questions
  1. IDS Rule Structure
  2. Rule Header Fields
  3. Rule Options
  4. Rule Actions
  5. Rule Syntax and Format
  6. Rule Categories and Classification
  7. Rule Tuning and Optimization
  8. Rule Testing and Validation

Packet Engineering

10 concepts · 35 questions
  1. Packet Structure
  2. Header Analysis
  3. Payload Inspection
  4. Packet Crafting
  5. Checksum Calculation
  6. Fragmentation and Reassembly
  7. TCP Session Analysis
  8. Protocol Encapsulation
  9. Packet Timing and Ordering
  10. Traffic Flow Patterns

Fragmentation

6 concepts · 36 questions
  1. Fragmentation Basics
  2. Fragment Offset and Flags
  3. Fragmentation Process
  4. Reassembly Process
  5. Fragmentation Attacks and Evasion
  6. Fragmentation in Network Analysis

Application Protocols

11 concepts · 45 questions
  1. HTTP Protocol Analysis
  2. HTTPS/TLS Analysis
  3. DNS Protocol Analysis
  4. SMTP Protocol Analysis
  5. POP3 and IMAP Analysis
  6. FTP Protocol Analysis
  7. Telnet and SSH Analysis
  8. DHCP Protocol Analysis
  9. SNMP Protocol Analysis
  10. Application Protocol Identification
  11. Application Layer Anomaly Detection
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCIA, so none is invented.