
GIAC Certified Intrusion Analyst
Domain 2Objective 1
Network Forensics and Traffic Analysis GCIA Practice Questions (Page 7)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 31–35
- 31
In a TCP handshake, which sequence of flags is used to establish a connection?
Select an answer first - 32
During a packet analysis, an analyst sees a TCP stream with the SYN, SYN-ACK, ACK handshake, followed by a series of packets with the PSH and ACK flags set. The payload contains an HTTP GET request, but the response is fragmented across multiple packets. The analyst needs to determine the full HTTP response body. What is the most appropriate next step?
Select an answer first - 33
An incident response team is investigating a breach that occurred over a weekend. They have NetFlow records, firewall logs, and a partial packet capture that starts on Monday morning. The team needs to determine the initial entry point and the scope of the breach. Which approach is most effective?
Select an answer first - 34
In a legal investigation, why is it important to maintain a proper chain of custody for network traffic captures?
Select an answer first - 35
Which type of log is most likely to provide evidence of a user's authentication activity on a Windows system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.