
GIAC Certified Intrusion Analyst
Domain 3Objective 1
IDS Fundamentals and Network Architecture GCIA Practice Questions (Page 6)
Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 26–30
- 26
A security analyst is evaluating a new IDS. The vendor claims it can detect previously unknown attacks by learning normal network behavior. However, the analyst is concerned about the number of false positives. Which detection method is the vendor describing, and what is a key trade-off?
Select an answer first - 27
What is a common method to ensure an IDS sensor on a switched network can see all traffic on a segment?
Select an answer first - 28
Which data source provides the most detailed information about the content of network communications?
Select an answer first - 29
Which type of intrusion detection system monitors network traffic by analyzing packet headers and payloads?
Select an answer first - 30
An organization needs to detect an attacker who has already gained a foothold on a single employee laptop and is attempting to modify system files and create new user accounts. The network team has a NIDS at the perimeter. Which additional control would provide the most direct visibility into these host-level activities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.