
GIAC Certified Intrusion Analyst
Domain 4Objective 2
Fragmentation GCIA Practice Questions (Page 6)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 26–30
- 26
A network engineer is troubleshooting a connectivity issue. A host sends a 4000-byte UDP packet (including 20-byte IP header and 8-byte UDP header) to a destination over a path with an MTU of 1500 bytes. The engineer captures the fragments. How many fragments will be created?
Select an answer first - 27
A security analyst is investigating a possible denial-of-service attack. The capture shows a flood of fragmented packets with random identification values, all with the same source IP. The destination host is consuming high CPU and memory. What is the most likely attack?
Select an answer first - 28
A network analyst is examining a packet capture and sees a fragment with the MF flag set and a fragment offset of 0. What does this indicate about the fragment?
Select an answer first - 29
An analyst is using Wireshark to inspect fragmented traffic. They see a series of fragments with the same identification but notice that one fragment has a different protocol field in the IP header. What should the analyst conclude?
Select an answer first - 30
When analyzing fragmented traffic in Wireshark, what indicates a potential reassembly problem?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.