Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 2Objective 1

Network Forensics and Traffic Analysis GCIA Practice Questions (Page 1)

Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 1–5

  1. 1expert · hard

    A forensic analyst is investigating a data breach. The packet capture contains an FTP session where a file was transferred, but the capture is incomplete: some data packets are missing, and the TCP stream has gaps. The analyst needs to extract the file for malware analysis. The capture also includes a second FTP session that appears complete. Which approach is most likely to yield a usable file?

    Select an answer first
  2. 2application · medium

    A company is preparing for a potential legal case involving a network intrusion. The legal team requires that network evidence be preserved in a way that maintains its integrity and adheres to the chain of custody. What is the most important practice to follow when capturing and handling network traffic?

    Select an answer first
  3. 3application · medium

    A security analyst needs to capture traffic on a critical production segment to investigate a suspected data exfiltration. The switch is a high-end model with limited SPAN resources, and the segment carries a mix of normal business traffic and occasional large file transfers. The analyst must ensure that no packets are dropped during peak utilization and that the capture does not disrupt production. Which approach best meets these requirements?

    Select an answer first
  4. 4foundation · easy

    When analyzing a packet capture, which combination of fields uniquely identifies a TCP connection?

    Select an answer first
  5. 5application · medium

    During a packet analysis, an analyst observes a TCP connection where the initial sequence number (ISN) is set to 0 and the window size is set to a very small value. The connection is to a known malicious IP address. What does this combination of characteristics most likely indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.