
GIAC Certified Intrusion Analyst
Domain 2Objective 2
SiLK and Other Traffic Analysis Tools GCIA Practice Questions (Page 10)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
16concepts
Questions 46–49
- 46
An analyst is investigating a possible malware infection that communicates over HTTP. The analyst has SiLK flow data and Zeek logs. The analyst needs to identify the internal hosts that communicated with a known malicious IP, and then determine if any of those hosts downloaded a specific file. Which approach best leverages both tools?
Select an answer first - 47
An analyst is monitoring a network for a potential DDoS attack. The analyst needs to detect a sudden increase in the number of flows per minute. The SiLK repository contains flow data. Which command would best help the analyst see the flow rate over time?
Select an answer first - 48
An analyst is using SiLK to investigate a potential beaconing pattern from an internal host to an external IP. The analyst wants a visual representation of the communication over time to spot periodic connections. Which SiLK tool provides this visualization?
Select an answer first - 49
Which tcpdump option is used to write captured packets to a file?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.