
GIAC Certified Intrusion Analyst
Domain 2Objective 3
Tcpdump Filters GCIA Practice Questions (Page 3)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
10concepts
Questions 11–15
- 11
Which tcpdump option writes captured packets to a file in pcap format?
Select an answer first - 12
An analyst is examining a pcap file and needs to find TCP packets where the IP header has the 'Don't Fragment' (DF) bit set. Which tcpdump filter expression can be used to identify these packets?
Select an answer first - 13
Which tcpdump option limits the number of packets captured to 100?
Select an answer first - 14
Which tcpdump primitive is used to match a range of ports?
Select an answer first - 15
An analyst is monitoring for ICMP echo requests (ping) from a specific host 10.0.0.5. Which tcpdump filter expression captures only ICMP echo requests from that host?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.