Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 3Objective 3

Intrusion Detection System Rules GCIA Practice Questions (Page 1)

Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
8concepts

Questions 1–5

  1. 1foundation · easy

    In a Snort rule, which action causes the IDS to generate an alert and log the packet?

    Select an answer first
  2. 2foundation · easy

    What does the direction operator '->' in a rule header indicate?

    Select an answer first
  3. 3expert · hard

    An analyst is writing a rule to detect a web application attack that sends a specific string in the URI. The analyst wants to ensure the rule only matches the URI, not the body or headers. Which rule option is essential?

    Select an answer first
  4. 4foundation · easy

    Which rule option is used to limit the number of times a rule alerts within a specified time period?

    Select an answer first
  5. 5application · medium

    An analyst has written a new Snort rule to detect a specific exploit. Before deploying it to production, the analyst wants to verify that the rule fires on the exploit traffic and does not fire on normal traffic. Which approach is the most controlled and reliable method?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.