
GIAC Network Forensic Analyst
Domain 1Objective 1
Common Network Protocols GNFA Practice Questions (Page 3)
Part of the Network Fundamentals and Architecture domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 9–16 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
13concepts
Questions 11–15
- 11
Besides an IP address, which of the following parameters can a DHCP server provide to a client?
Select an answer first - 12
A forensic analyst is examining a web server's access logs and sees a series of requests to a login page. The analyst notices that the requests are using HTTP (port 80) instead of HTTPS. What is the primary security concern with this observation?
Select an answer first - 13
A security analyst is investigating a suspicious HTTPS connection. The analyst captures the TLS handshake and sees that the server's certificate is self-signed. What is the most significant risk associated with this connection?
Select an answer first - 14
Which field in an Ethernet frame is used to indicate the upper-layer protocol encapsulated in the payload?
Select an answer first - 15
A security analyst is reviewing a capture of a file transfer from an internal host to an external server. The analyst sees a three-way handshake followed by data transfer, then a FIN, ACK exchange. The analyst also notices that every data segment received by the server is acknowledged individually. Which transport-layer characteristic is most clearly demonstrated in this capture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.