
GIAC Certified Intrusion Analyst
Domain 2Objective 4
Wireshark Fundamentals GCIA Practice Questions (Page 1)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 1–5
- 1
Which Wireshark statistics tool provides a tree view showing the percentage of packets and bytes for each protocol in the capture?
Select an answer first - 2
During an incident, an analyst captured traffic between a compromised host and a command-and-control server. The analyst needs to extract the full HTTP request and response exchanged during a specific connection to understand the attacker's commands. The capture contains many HTTP connections. What is the most efficient way to view the complete HTTP conversation for that specific connection?
Select an answer first - 3
An analyst is investigating a suspicious HTTP request and wants to see the full request and response headers and body. Which Wireshark feature should be used?
Select an answer first - 4
In the Capture Options dialog, which setting limits the size of each capture file so that a new file is started automatically when the limit is reached?
Select an answer first - 5
Which Wireshark feature allows you to export only the packets that are currently displayed (after applying a display filter) to a new capture file?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.