
GIAC Certified Intrusion Analyst
Domain 2Objective 1
Network Forensics and Traffic Analysis GCIA Practice Questions (Page 9)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 41–45
- 41
Which technique is commonly used to anonymize IP addresses in a packet capture while preserving the ability to analyze communication patterns?
Select an answer first - 42
When analyzing fragmented IP packets, what field is used to reassemble the fragments in the correct order?
Select an answer first - 43
A network analyst is reviewing NetFlow records and notices a large number of flows from an internal host to a single external IP address on port 443, with each flow lasting only a few seconds and transferring a small amount of data. The analyst suspects beaconing behavior. Which additional flow characteristic would most strongly support this hypothesis?
Select an answer first - 44
What is a primary advantage of using flow records (e.g., NetFlow) over full packet capture for network monitoring?
Select an answer first - 45
An analyst is examining a pcap file from a compromised host. The traffic shows an HTTP POST to a malicious server, and the analyst suspects that a file was uploaded. The file is not visible in the initial packet list. What is the most effective way to extract the file from the capture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.