
GIAC Certified Intrusion Analyst
Domain 3Objective 3
Intrusion Detection System Rules GCIA Practice Questions (Page 2)
Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 6–10
- 6
An organization has hundreds of IDS rules. The analyst wants to categorize them so that alerts can be filtered by attack type, such as 'web-application-attack' or 'attempted-admin'. Which rule component should be used to achieve this?
Select an answer first - 7
In a typical Snort-style intrusion detection rule, which two major structural sections are always present?
Select an answer first - 8
Which rule action is only effective when the sensor is deployed inline as an IPS?
Select an answer first - 9
An analyst is reviewing a Snort rule and needs to identify which part of the rule defines the action to take when the rule matches. The rule is: alert tcp any any -> any 80 (msg:"web"; sid:1000004;). Which component is the action?
Select an answer first - 10
What punctuation is used to separate multiple rule options inside the parentheses?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.