
GIAC Certified Intrusion Analyst
Domain 4Objective 3
Application Protocols GCIA Practice Questions (Page 5)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
11concepts
Questions 21–25
- 21
When analyzing network traffic, which characteristic is a key indicator that the traffic is Telnet rather than SSH?
Select an answer first - 22
In an SMTP session, the client sends the command "EHLO example.com". What is the purpose of this command?
Select an answer first - 23
In a DHCP packet capture, which message type is sent by the client to discover available DHCP servers?
Select an answer first - 24
An analyst is comparing two remote administration sessions in a packet capture. Session A uses port 22 and the payload is encrypted. Session B uses port 23 and the payload contains plaintext commands like 'ls -la' and 'cat /etc/passwd'. Which session poses a greater security risk, and why?
Select an answer first - 25
A forensic analyst is examining a pcap from a compromised email account. The analyst sees a session on port 143 that includes the commands 'a001 LOGIN user@company.com password', 'a002 SELECT INBOX', 'a003 FETCH 1 BODY[]', and 'a004 LOGOUT'. Which of the following is the most significant security concern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.