
GIAC Certified Intrusion Analyst
Domain 4Objective 3
Application Protocols GCIA Practice Questions (Page 2)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
11concepts
Questions 6–10
- 6
In an FTP session, the client sends the command "RETR report.pdf". What is the server expected to do?
Select an answer first - 7
In a DHCP packet, which option field is used to specify the IP address of the DNS server that the client should use?
Select an answer first - 8
An analyst is examining a packet capture and sees a TCP session on port 23. The payload contains the string 'Password: ' followed by the characters 's3cr3t' in plaintext. The session continues with the server sending a command prompt. Which protocol is in use, and what is the primary security concern?
Select an answer first - 9
A DHCP server administrator is troubleshooting a report of IP address conflicts. In a pcap, they see a DHCPREQUEST from a client with the 'Requested IP Address' option set to 192.168.1.50, and the server responds with a DHCPNAK. The client then sends a new DHCPDISCOVER. Which of the following is the most likely reason for the DHCPNAK?
Select an answer first - 10
In an SMTP transaction, what is the purpose of the DATA command?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.