
GIAC Certified Intrusion Analyst
Domain 1Objective 5
UDP and ICMP GCIA Practice Questions (Page 2)
Part of the Network Fundamentals domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~33–56 in this domain), expect 7–11 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
6concepts
Questions 6–10
- 6
A packet capture shows a large number of ICMP echo requests sent to a single host from many different source IP addresses. What does this pattern most likely indicate?
Select an answer first - 7
An analyst is reviewing a packet capture and sees a UDP packet with source port 68 and destination port 67. What is this packet?
Select an answer first - 8
Under which condition does a router generate an ICMP error message?
Select an answer first - 9
A network analyst is examining a packet capture and sees an ICMP message with type 3 and code 1. What is the meaning of this message?
Select an answer first - 10
A security analyst is reviewing a packet capture and sees a large number of UDP packets from a single source IP to a single destination IP on port 53. The packets are all the same size and are sent at a constant rate. The analyst suspects a DNS amplification attack. What characteristic of UDP makes this attack possible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.