
GIAC Certified Intrusion Analyst
Domain 3Objective 3
Intrusion Detection System Rules GCIA Practice Questions (Page 6)
Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 26–30
- 26
Which rule option is used to check the TCP control bits in a packet?
Select an answer first - 27
A Snort rule is designed to detect a specific exploit that sends a TCP packet with a particular payload. The rule currently uses the 'content' option to match the payload. In testing, the rule fires on the exploit but also on legitimate traffic that contains the same payload. The analyst has confirmed that the exploit always sets the URG flag, while legitimate traffic does not. Which change to the rule would best reduce false positives while maintaining detection?
Select an answer first - 28
Which method is commonly used to validate that an IDS rule fires correctly?
Select an answer first - 29
A company runs Suricata in inline mode at the internet gateway. A rule that drops traffic to a known malicious IP is also dropping legitimate traffic from a partner network that uses the same IP range. The analyst must stop the false drops while still blocking the malicious IP. Which approach is the best trade-off?
Select an answer first - 30
Which part of an IDS rule contains the rule's action, protocol, source and destination addresses, and ports?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.