
GIAC Certified Intrusion Analyst
Domain 2Objective 1
Network Forensics and Traffic Analysis GCIA Practice Questions (Page 10)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 46–47
- 46
A network analyst is reviewing NetFlow records and notices a single internal host communicating with an external IP on port 53 using UDP, with flow records showing small packet sizes and consistent intervals every 10 minutes over several days. The analyst needs to determine if this is a DNS issue or something else. Which additional data source would most directly confirm whether this is legitimate DNS traffic?
Select an answer first - 47
A security analyst is reviewing a packet capture and sees a TCP connection with the SYN flag set, followed immediately by a RST, repeated every few seconds from the same source IP to a single destination port 445. The source IP is a known internal workstation. Which interpretation is most consistent with this pattern?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.