Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 3Objective 3

Intrusion Detection System Rules GCIA Practice Questions (Page 2)

Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
8concepts

Questions 6–10

  1. 6application · medium

    An organization has hundreds of IDS rules. The analyst wants to categorize them so that alerts can be filtered by attack type, such as 'web-application-attack' or 'attempted-admin'. Which rule component should be used to achieve this?

    Select an answer first
  2. 7foundation · easy

    In a typical Snort-style intrusion detection rule, which two major structural sections are always present?

    Select an answer first
  3. 8foundation · easy

    Which rule action is only effective when the sensor is deployed inline as an IPS?

    Select an answer first
  4. 9application · easy

    An analyst is reviewing a Snort rule and needs to identify which part of the rule defines the action to take when the rule matches. The rule is: alert tcp any any -> any 80 (msg:"web"; sid:1000004;). Which component is the action?

    Select an answer first
  5. 10foundation · easy

    What punctuation is used to separate multiple rule options inside the parentheses?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.