
GIAC Certified Intrusion Analyst
Domain 4Objective 1
Packet Engineering GCIA Practice Questions (Page 6)
Part of the Packet Analysis and Engineering domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 26–30
- 26
An analyst is looking at a packet capture and sees an Ethernet frame with a type field of 0x0806. Inside the payload, there is a hardware type of 1, protocol type of 0x0800, and a 6-byte sender hardware address. What protocol is this packet, and what is its purpose?
Select an answer first - 27
When inspecting application-layer data in a packet capture, which protocol would you expect to see if the payload contains a 'GET /index.html HTTP/1.1' request?
Select an answer first - 28
An analyst is investigating a potential denial-of-service attack. The capture shows many IP fragments with the same source and destination, but the fragments have overlapping offsets and inconsistent payload sizes. What is the most likely attack technique and the best defense?
Select an answer first - 29
Which application-layer protocol is used to resolve a hostname to an IP address?
Select an answer first - 30
In a pcap, you see a TCP stream where packet 3 is a retransmission of packet 1, but packet 2 (which was sent after packet 1) was not retransmitted. The timestamps show packet 1 at time 0.000, packet 2 at 0.001, and packet 3 at 0.200. What does this pattern indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.