Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 3Objective 2

Advanced IDS Concepts GCIA Practice Questions (Page 1)

Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
1concept

Questions 1–5

  1. 1application · medium

    A security analyst notices that an IDS sensor is generating a high volume of alerts for a legitimate internal application that performs large database exports between two servers. The analyst has verified the traffic is benign and wants to reduce noise while still detecting genuine threats from the same source IP. Which approach best addresses this situation?

    Select an answer first
  2. 2application · medium

    An organization's IDS is missing attacks that use overlapping fragments. The analyst wants to ensure the sensor can detect these attacks. What is the best configuration change?

    Select an answer first
  3. 3application · medium

    A security team has deployed a new IDS and is receiving thousands of alerts daily, most of which are false positives from internal monitoring tools. The team has limited staff and needs to prioritize their investigation efforts. Which approach is most effective for managing this alert volume?

    Select an answer first
  4. 4expert · hard

    A security team has an IDS that generates a high volume of alerts. After tuning, they have reduced false positives but are now concerned about missing true positives. The team has limited analyst resources and needs to balance detection coverage with the ability to investigate alerts. Which approach best achieves this balance?

    Select an answer first
  5. 5application · medium

    An analyst is reviewing IDS alerts and finds that an attacker is sending fragmented IP packets that, when reassembled, form a malicious payload. The IDS is configured to inspect only the first fragment of each packet. What is the most effective way to improve detection of this evasion technique?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.