
GIAC Certified Intrusion Analyst
Domain 2Objective 3
Tcpdump Filters GCIA Practice Questions (Page 2)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
10concepts
Questions 6–10
- 6
Which tcpdump option sets the snapshot length (snaplen) to 512 bytes?
Select an answer first - 7
Which tcpdump command reads packets from a capture file named traffic.pcap?
Select an answer first - 8
Which tcpdump filter matches packets where the source IP is 10.0.0.1?
Select an answer first - 9
An analyst is capturing traffic and wants to see the timestamp in Unix epoch format for each packet. Which tcpdump option should be used?
Select an answer first - 10
An analyst is monitoring a network and needs to capture only TCP packets that have the SYN flag set and are destined for port 443 on any host. Which tcpdump filter expression achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.