
GIAC Network Forensic Analyst
The GIAC Network Forensic Analyst (GNFA) certification validates advanced skills in network forensic investigations, from analyzing network traffic captures and metadata to reverse-engineering protocols and identifying malicious activity. Designed for incident responders, forensic analysts, and threat hunters, GNFA holders are equipped to process both normal and abnormal network activity and deliver actionable intelligence. Earning GNFA demonstrates hands-on, real-world capability in one of cybersecurity's most critical investigative disciplines.
363 practice questions · Updated 2026-07-30
GNFA Curriculum
Every domain, objective, and concept the GNFA exam measures.
- TCP/IP Protocol Suite
- Ethernet and MAC Addressing
- IP Addressing and Subnetting
- ARP and Neighbor Discovery
- ICMP and ICMPv6
- TCP and UDP Fundamentals
- DNS Resolution
- DHCP Operation
- HTTP and HTTPS
- SMTP, POP3, and IMAP
- FTP and TFTP
- TLS and SSL
- Network Ports and Services
- Network Topologies
- OSI and TCP/IP Models
- Network Devices
- IP Addressing and Subnetting
- Network Protocols
- Network Segmentation
- Network Traffic Flow
- NetFlow Fundamentals
- NetFlow Data Structure
- NetFlow Collection and Export
- NetFlow Analysis Techniques
- Attack Detection via NetFlow
- Visualization Principles
- NetFlow Visualization Tools
- Interpreting Visualizations
- Correlating NetFlow with Other Data
- Reporting and Communication
- Protocol Identification
- Protocol Structure Analysis
- State Machine Modeling
- Session Reassembly
- Payload Decoding
- Protocol Anomaly Detection
- Custom Protocol Reverse Engineering
- Proxy Fundamentals
- Open Source Proxy Types
- Proxy Configuration and Deployment
- Traffic Logging and Analysis
- Proxy Security Features
- Integration with Monitoring Tools
- Security Event Logging Fundamentals
- Incident Logging Fundamentals
- Log Sources and Types
- Log Collection and Aggregation
- Log Retention and Storage
- Log Integrity and Protection
- Log Analysis and Correlation
- Logging Best Practices
- Encryption Fundamentals
- Common Encryption Algorithms
- Encoding vs. Encryption
- Common Encoding Schemes
- Encryption in Network Protocols
- Decryption and Cryptanalysis Basics
- Tools for Encryption Analysis
- Wireless Frame Types and Structure
- Wireless Capture Acquisition
- Wireless Authentication and Association Analysis
- Deauthentication and Disassociation Attack Detection
- Wireless Encryption and Key Analysis
- Rogue Access Point Identification
- Client Behavior and Association Patterns
- Wireless Geolocation and Signal Analysis
- Wireless Attack Artifacts and Evidence Extraction
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GNFA, so none is invented.