
GIAC Certified Intrusion Analyst
Domain 1Objective 5
UDP and ICMP GCIA Practice Questions (Page 6)
Part of the Network Fundamentals domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~33–56 in this domain), expect 7–11 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
6concepts
Questions 26–30
- 26
A network engineer is troubleshooting a slow application and suspects packet loss. They run a ping with a large payload and observe that the first few packets get replies, but then they start receiving 'Destination Unreachable - Fragmentation needed and DF set' messages. What is the most likely cause?
Select an answer first - 27
Which ICMP message type is used to test reachability of a host?
Select an answer first - 28
During a packet analysis, an analyst sees a UDP packet with source port 12345, destination port 53, length 35, and checksum 0x0000. The analyst knows that the checksum is 0x0000. What does this indicate?
Select an answer first - 29
In a packet capture, you see a UDP packet with a destination port of 53. What application is most likely associated with this traffic?
Select an answer first - 30
An analyst is reviewing a packet capture and sees a UDP packet with a source port of 53 and a destination port of 53. The packet has a length of 100 bytes. What is the most likely scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.