
GIAC Certified Intrusion Analyst
Domain 2Objective 4
Wireshark Fundamentals GCIA Practice Questions (Page 2)
Part of the Traffic Analysis and Tools domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~26–43 in this domain), expect 7–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 6–10
- 6
Which display filter would show only packets that are DNS queries or responses?
Select an answer first - 7
Which Wireshark feature allows you to reassemble and view the full contents of a TCP conversation, such as an HTTP request and response, in a single window?
Select an answer first - 8
An analyst is investigating a possible DNS tunneling attack. The analyst wants to see only DNS queries that are longer than 100 characters and are being sent to a specific DNS server at 8.8.8.8. Which display filter accomplishes this?
Select an answer first - 9
In the packet details pane, what does the 'Frame' section typically show?
Select an answer first - 10
An analyst is examining a TCP stream that contains a file transfer. The stream has several retransmissions and out-of-order packets. The analyst needs to extract the exact data that was successfully received by the application, excluding retransmissions. What is the most reliable method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIA” is a trademark of its owner, used for identification only.