
GIAC Certified Intrusion Analyst
Domain 4Objective 3
Application Protocols GCIA Practice Questions (Page 1)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
11concepts
Questions 1–5
- 1
A security analyst is reviewing a packet capture and sees traffic on TCP port 8080. The payload contains the ASCII string 'GET /index.html HTTP/1.1' followed by 'Host: internal.example.com'. The analyst also notices that the source and destination IPs are both internal addresses. Which application protocol is most likely in use, and what is a key consideration for identification?
Select an answer first - 2
An analyst is examining HTTP traffic and sees a request with the method 'PROPFIND' to a web server. The server responds with '501 Not Implemented'. The analyst also notices that the User-Agent header is 'Microsoft-WebDAV-MiniRedir/10.0.16299'. What is the most likely explanation for this traffic?
Select an answer first - 3
While reviewing a packet capture from a web server, you notice a series of requests to /admin/login.php that return HTTP/1.1 302 Found responses. Each request uses the POST method and includes a body containing 'username=admin&password=letmein'. The responses include a Location header pointing to /admin/dashboard.php. What is the most likely explanation for this traffic pattern?
Select an answer first - 4
A packet capture shows TCP traffic to port 25 on a remote server. Which application protocol is most likely being used?
Select an answer first - 5
A network security analyst is comparing two remote administration sessions in a pcap. Session A is on port 23 and contains the text 'Password: ' followed by what appears to be a password in plaintext. Session B is on port 22 and contains a TLS-like handshake followed by encrypted data. The analyst needs to determine which session is more likely to be an attacker's remote access. Which of the following is the most accurate conclusion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.