Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Intrusion Analyst

Domain 2Objective 3

Tcpdump Filters GCIA Practice Questions (Page 3)

Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    Which tcpdump option writes captured packets to a file in pcap format?

    Select an answer first
  2. 12expert · hard

    An analyst is examining a pcap file and needs to find TCP packets where the IP header has the 'Don't Fragment' (DF) bit set. Which tcpdump filter expression can be used to identify these packets?

    Select an answer first
  3. 13foundation · easy

    Which tcpdump option limits the number of packets captured to 100?

    Select an answer first
  4. 14foundation · easy

    Which tcpdump primitive is used to match a range of ports?

    Select an answer first
  5. 15application · medium

    An analyst is monitoring for ICMP echo requests (ping) from a specific host 10.0.0.5. Which tcpdump filter expression captures only ICMP echo requests from that host?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.