Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 2Objective 1

Network Forensics and Traffic Analysis GCIA Practice Questions (Page 3)

Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 11–15

  1. 11expert · hard

    An organization needs to capture traffic on a 40 Gbps backbone link for security monitoring. The budget allows for either a commercial capture appliance with a dedicated tap or a software-based capture using a SPAN port. The monitoring team needs to retain full packets for 30 days and must be able to reconstruct sessions. Which solution is most appropriate?

    Select an answer first
  2. 12expert · hard

    A network analyst is investigating a potential data exfiltration. NetFlow records show a host sending large amounts of data to an external IP on port 443. The analyst also has firewall logs showing that the connection was allowed. The analyst needs to determine if the traffic is legitimate HTTPS or a covert channel. Which approach is most effective?

    Select an answer first
  3. 13expert · hard

    A security team needs to share a packet capture with an external threat intelligence firm for collaborative analysis. The capture contains sensitive customer data, including IP addresses and email addresses. The team must anonymize the data while preserving the ability to analyze network behavior and detect anomalies. Which approach is most appropriate?

    Select an answer first
  4. 14application · medium

    A forensic analyst needs to share a packet capture with a third-party threat intelligence vendor for analysis, but the capture contains sensitive employee IP addresses and usernames. The analyst must anonymize the data while preserving the ability to analyze protocol behavior and detect anomalies. Which approach best meets this requirement?

    Select an answer first
  5. 15foundation · easy

    What is a key characteristic of a forensic report intended for a legal audience?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.