
GIAC Certified Intrusion Analyst
Domain 3Objective 1
IDS Fundamentals and Network Architecture GCIA Practice Questions (Page 2)
Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 6–10
- 6
An analyst is monitoring a network and notices that a DNS server is receiving an unusually high number of queries for a domain that does not exist. The queries are coming from many different internal hosts. Which type of analysis would best help determine if this is a malicious activity?
Select an answer first - 7
A security team is comparing two IDS products. Product A uses a database of known attack patterns. Product B tracks the state of TCP sessions and flags packets that violate protocol standards, such as a SYN packet arriving in the middle of an established session. Which detection method does Product B use?
Select an answer first - 8
An analyst notices that a NIDS has generated a high volume of alerts for a specific signature that matches a known exploit. Investigation shows that the exploit is not actually succeeding because the target systems are patched. The analyst wants to reduce the noise while still detecting the exploit if it becomes a real threat. What is the most appropriate action?
Select an answer first - 9
A NIDS alerts on a suspicious outbound connection from a finance workstation to an external IP. The analyst checks the alert and sees that the connection used an encrypted protocol. The analyst has access to the workstation's HIDS logs, which show no unusual processes. Which conclusion is most appropriate?
Select an answer first - 10
An analyst is investigating a slow and low data exfiltration that may have occurred over several weeks. The organization only has NetFlow records, not full packet captures. Which analysis technique is most likely to reveal the exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.