
GIAC Certified Intrusion Analyst
Domain 4Objective 3
Application Protocols GCIA Practice Questions (Page 4)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
11concepts
Questions 16–20
- 16
An analyst is examining a pcap and sees an HTTP request with the following headers: 'GET /login.php HTTP/1.1', 'Host: www.example.com', 'Content-Length: 0', and 'Cookie: sessionid=abc123'. The response is 'HTTP/1.1 302 Found' with a 'Location: /dashboard'. Which of the following best describes the interaction?
Select an answer first - 17
A security analyst is reviewing a DNS capture and sees a query for 'legit-service.com' with the QR bit set to 0. The response has the QR bit set to 1, the AA bit set to 1, and the answer section contains an A record for 203.0.113.10. The response also contains an additional section with an OPT record indicating EDNS0 support. The analyst notices that the response's transaction ID matches the query. Which of the following is the most significant finding?
Select an answer first - 18
In SNMPv1 and SNMPv2c, what is the purpose of the community string?
Select an answer first - 19
An analyst is reviewing SNMP traffic and sees a packet with a community string of 'private' and a PDU type of 0xA3 (SetRequest). The source IP is 10.0.0.50 and the destination is 10.0.0.1 on port 161. The OID in the packet is 1.3.6.1.2.1.1.5.0 (sysName) with a value of 'NewRouter'. What is the most likely security concern?
Select an answer first - 20
A security analyst is investigating a potential data exfiltration. The pcap shows a TLS session to an external IP on port 443. The analyst can see the ClientHello with an SNI of 'update.example.com' and a certificate that is self-signed. The analyst also sees that the session is using TLS 1.2. Which of the following is the most significant indicator of malicious activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.