
GIAC Certified Intrusion Analyst
Domain 2Objective 1
Network Forensics and Traffic Analysis GCIA Practice Questions (Page 4)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 16–20
- 16
Which section of a forensic report should include the analyst's overall assessment of what occurred during the incident?
Select an answer first - 17
What is the purpose of TCP stream reassembly in network traffic analysis?
Select an answer first - 18
Which DNS record type is used to map a hostname to an IPv4 address?
Select an answer first - 19
What is the primary purpose of network forensics in the context of incident response?
Select an answer first - 20
What is the goal of anonymizing IP addresses in a packet capture before sharing it with third parties?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.