
GIAC Network Forensic Analyst
Domain 1Objective 1
Common Network Protocols GNFA Practice Questions (Page 11)
Part of the Network Fundamentals and Architecture domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 9–16 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
13concepts
Questions 51–55
- 51
A network analyst is explaining to a junior analyst why a packet capture shows an ARP request before a TCP handshake. Which layer of the TCP/IP model is responsible for the ARP request?
Select an answer first - 52
Which of the following protocols uses both TCP and UDP port 53?
Select an answer first - 53
Which statement correctly describes a key difference between IPv4 and IPv6 addressing?
Select an answer first - 54
A network analyst is troubleshooting a connectivity issue in a mixed IPv4/IPv6 network. A Windows host is unable to reach a server on the same subnet. The analyst captures traffic and sees the host sending Neighbor Solicitation (NS) messages for the server's IPv6 address, but no Neighbor Advertisement (NA) is received. What is the most likely cause?
Select an answer first - 55
An analyst is investigating a data exfiltration incident. The capture shows a client connecting to an external server on TCP port 25, sending a series of commands, and then receiving responses. The analyst also observes the client authenticating with a username and password. Which protocol is the client using, and what is its primary role in this scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.