
GIAC Certified Intrusion Analyst
Domain 2Objective 1
Network Forensics and Traffic Analysis GCIA Practice Questions (Page 6)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 26–30
- 26
In a TCP/IP packet, which header field identifies the upper-layer protocol that is encapsulated in the packet's payload?
Select an answer first - 27
Which device is physically inserted inline in a network link to provide a passive copy of all traffic for monitoring purposes?
Select an answer first - 28
Which tool is commonly used to extract files (e.g., images, documents) from a packet capture?
Select an answer first - 29
During an incident response, an analyst has a packet capture that contains an HTTP session where the server sent a large file in multiple TCP segments, but some segments were captured out of order and one segment is missing. The analyst needs to reconstruct the file for malware analysis. Which tool feature is most appropriate for this task?
Select an answer first - 30
An analyst is examining a pcap and sees an HTTP request with a 'Content-Length' header that is much larger than the actual payload size. The connection is to a known malicious server. What does this discrepancy most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.