Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 2Objective 3

Tcpdump Filters GCIA Practice Questions (Page 2)

Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
10concepts

Questions 6–10

  1. 6foundation · easy

    Which tcpdump option sets the snapshot length (snaplen) to 512 bytes?

    Select an answer first
  2. 7foundation · easy

    Which tcpdump command reads packets from a capture file named traffic.pcap?

    Select an answer first
  3. 8foundation · easy

    Which tcpdump filter matches packets where the source IP is 10.0.0.1?

    Select an answer first
  4. 9application · medium

    An analyst is capturing traffic and wants to see the timestamp in Unix epoch format for each packet. Which tcpdump option should be used?

    Select an answer first
  5. 10application · medium

    An analyst is monitoring a network and needs to capture only TCP packets that have the SYN flag set and are destined for port 443 on any host. Which tcpdump filter expression achieves this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.