Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Network Forensic Analyst

GNFA

The GIAC Network Forensic Analyst (GNFA) certification validates advanced skills in network forensic investigations, from analyzing network traffic captures and metadata to reverse-engineering protocols and identifying malicious activity. Designed for incident responders, forensic analysts, and threat hunters, GNFA holders are equipped to process both normal and abnormal network activity and deliver actionable intelligence. Earning GNFA demonstrates hands-on, real-world capability in one of cybersecurity's most critical investigative disciplines.

363 practice questions · Updated 2026-07-30

4Domains
8Objectives
67Concepts
363Questions

GNFA Curriculum

Every domain, objective, and concept the GNFA exam measures.

Common Network Protocols

13 concepts · 56 questions
  1. TCP/IP Protocol Suite
  2. Ethernet and MAC Addressing
  3. IP Addressing and Subnetting
  4. ARP and Neighbor Discovery
  5. ICMP and ICMPv6
  6. TCP and UDP Fundamentals
  7. DNS Resolution
  8. DHCP Operation
  9. HTTP and HTTPS
  10. SMTP, POP3, and IMAP
  11. FTP and TFTP
  12. TLS and SSL
  13. Network Ports and Services

Network Architecture

7 concepts · 39 questions
  1. Network Topologies
  2. OSI and TCP/IP Models
  3. Network Devices
  4. IP Addressing and Subnetting
  5. Network Protocols
  6. Network Segmentation
  7. Network Traffic Flow

  1. NetFlow Fundamentals
  2. NetFlow Data Structure
  3. NetFlow Collection and Export
  4. NetFlow Analysis Techniques
  5. Attack Detection via NetFlow
  6. Visualization Principles
  7. NetFlow Visualization Tools
  8. Interpreting Visualizations
  9. Correlating NetFlow with Other Data
  10. Reporting and Communication

Network Protocol Reverse Engineering

7 concepts · 47 questions
  1. Protocol Identification
  2. Protocol Structure Analysis
  3. State Machine Modeling
  4. Session Reassembly
  5. Payload Decoding
  6. Protocol Anomaly Detection
  7. Custom Protocol Reverse Engineering

Open Source Network Security Proxies

6 concepts · 45 questions
  1. Proxy Fundamentals
  2. Open Source Proxy Types
  3. Proxy Configuration and Deployment
  4. Traffic Logging and Analysis
  5. Proxy Security Features
  6. Integration with Monitoring Tools

Security Event and Incident Logging

8 concepts · 47 questions
  1. Security Event Logging Fundamentals
  2. Incident Logging Fundamentals
  3. Log Sources and Types
  4. Log Collection and Aggregation
  5. Log Retention and Storage
  6. Log Integrity and Protection
  7. Log Analysis and Correlation
  8. Logging Best Practices

Encryption and Encoding

7 concepts · 43 questions
  1. Encryption Fundamentals
  2. Common Encryption Algorithms
  3. Encoding vs. Encryption
  4. Common Encoding Schemes
  5. Encryption in Network Protocols
  6. Decryption and Cryptanalysis Basics
  7. Tools for Encryption Analysis

Wireless Network Analysis

9 concepts · 36 questions
  1. Wireless Frame Types and Structure
  2. Wireless Capture Acquisition
  3. Wireless Authentication and Association Analysis
  4. Deauthentication and Disassociation Attack Detection
  5. Wireless Encryption and Key Analysis
  6. Rogue Access Point Identification
  7. Client Behavior and Association Patterns
  8. Wireless Geolocation and Signal Analysis
  9. Wireless Attack Artifacts and Evidence Extraction
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GNFA, so none is invented.