
GIAC Certified Intrusion Analyst
Domain 4Objective 3
Application Protocols GCIA Practice Questions (Page 8)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
11concepts
Questions 36–40
- 36
In FTP, what is the purpose of the control connection?
Select an answer first - 37
An analyst observes an HTTP request with the method "BREW". This method is not defined in the HTTP specification. What type of anomaly does this represent?
Select an answer first - 38
In a packet capture, you observe a TCP handshake followed by a TLS ClientHello message. What is the purpose of the ClientHello message?
Select an answer first - 39
An analyst is examining a pcap that contains a TLS 1.3 handshake between a client and a server. The analyst needs to determine the application-layer protocol being used (e.g., HTTP/2, SMTP, or custom). Which approach is most effective given the capture contains only the TLS handshake and encrypted application data?
Select an answer first - 40
In a DNS packet, the header flags indicate that the response is a normal answer, but the Answer section contains a record type that does not match the Question type. What kind of anomaly is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.