Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 3Objective 1

IDS Fundamentals and Network Architecture GCIA Practice Questions (Page 3)

Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
8concepts

Questions 11–15

  1. 11application · medium

    A NIDS generates an alert for a signature that matches a known web application attack. The analyst reviews the alert and sees that the source IP is an internal scanner that the security team uses for vulnerability assessments. The scanner is scheduled to run during this time. What should the analyst do first?

    Select an answer first
  2. 12application · medium

    A company has a flat network with no internal segmentation. All servers and workstations are on the same VLAN. The security team wants to deploy a single NIDS sensor to monitor all internal traffic. What is the most effective way to get traffic to the sensor?

    Select an answer first
  3. 13application · medium

    An analyst is investigating a possible data exfiltration. The NIDS did not alert, but the analyst has access to NetFlow records. Which type of analysis is most appropriate using NetFlow data?

    Select an answer first
  4. 14expert · hard

    An analyst is investigating a suspected slow data exfiltration that has been occurring over several weeks. The NIDS has not generated any alerts because the traffic volumes are within normal baseline. The analyst suspects that data is being sent in small, encrypted chunks to a cloud storage service. Which data source would be most useful to detect this activity?

    Select an answer first
  5. 15foundation · easy

    Which component of an IDS is responsible for notifying analysts when a suspicious event is detected?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.