Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 4Objective 3

Application Protocols GCIA Practice Questions (Page 9)

Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
11concepts

Questions 41–45

  1. 41application · medium

    A network analyst is investigating a suspected DNS tunneling incident. In a packet capture, they see many DNS queries for subdomains of a domain controlled by an attacker. Each query is a standard A record request, and the subdomain labels contain base64-encoded data. The responses are A records with IP addresses that appear to be from a public DNS server. Which DNS header field or section would most likely contain the exfiltrated data if the attacker is using DNS tunneling?

    Select an answer first
  2. 42foundation · easy

    When analyzing HTTPS traffic in a packet capture, why is it generally not possible to view the full contents of HTTP requests and responses?

    Select an answer first
  3. 43application · medium

    An analyst is inspecting SNMP traffic and sees a packet with a community string of 'public' and a PDU type of 0xA0 (GetRequest). The source IP is 10.0.0.50 and the destination is 10.0.0.1 on port 161. What is the most likely purpose of this packet?

    Select an answer first
  4. 44foundation · easy

    In IMAP, which command is used to select a mailbox for reading messages?

    Select an answer first
  5. 45expert · hard

    An email security analyst is reviewing SMTP traffic and sees a session where the client sends 'EHLO client.example.com' and the server responds with '250-AUTH LOGIN PLAIN'. The client then sends 'AUTH LOGIN' and the server responds with '334 VXNlcm5hbWU6'. The client sends a base64-encoded username and password. What is the most likely security concern with this SMTP authentication method?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCIA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.