
GIAC Certified Intrusion Analyst
Domain 3Objective 3
Intrusion Detection System Rules GCIA Practice Questions (Page 7)
Part of the IDS Concepts and Architecture domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 31–35
- 31
A Suricata rule is generating a high volume of alerts for a legitimate internal service. The analyst has determined that the alerts are true positives for the service's normal behavior, but they are not security incidents. The analyst wants to reduce the alert volume while still detecting actual attacks that use the same service. The analyst has identified that attacks use a specific pattern in the payload that is not present in normal traffic. Which tuning approach is the most effective?
Select an answer first - 32
An analyst is organizing a large set of IDS rules. The team wants to quickly identify rules that detect web application attacks and correlate them with CVE identifiers. Which rule components should be used to achieve this?
Select an answer first - 33
An analyst has written a new Snort rule to detect a specific exploit. The rule uses a content match that is known to be present in the exploit. In testing, the rule fires on the exploit traffic but also on a legitimate application that uses the same byte sequence. The analyst needs to reduce false positives without losing detection of the exploit. The analyst has access to a packet capture of both the exploit and the legitimate traffic. Which approach is the most effective?
Select an answer first - 34
An analyst is writing a rule to detect suspicious traffic from any external host to an internal mail server at 192.168.1.10 on port 25. The rule should only match TCP traffic. Which rule header is correct?
Select an answer first - 35
A Snort rule is designed to detect a specific exploit that sends a TCP packet with the SYN flag set and a specific payload. The analyst notices the rule is also firing on normal TCP handshakes that contain the same payload. Which rule option should be added to make the rule more specific to the exploit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.