
GIAC Network Forensic Analyst
Domain 4Objective 1
Encryption and Encoding GNFA Practice Questions (Page 4)
Part of the Advanced Analysis Techniques domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 16–20
- 16
A company needs to securely exchange symmetric keys between two servers over an untrusted network. They want to use a protocol that provides forward secrecy. Which key exchange method should they choose?
Select an answer first - 17
An analyst is investigating an encrypted TLS session and has obtained the session keys from the server. Which forensic tool feature would allow the analyst to decrypt the captured traffic in Wireshark?
Select an answer first - 18
An analyst extracts the following string from a network capture: 'SGVsbG8gV29ybGQ='. What is the most likely encoding scheme used?
Select an answer first - 19
An analyst is investigating a PCAP where a client and server negotiated a weak cipher suite. The analyst wants to attempt to recover the plaintext. Which approach is most likely to succeed?
Select an answer first - 20
In a network capture, an analyst sees that a client and server are using a custom encryption scheme that always encrypts the same plaintext block to the same ciphertext block. Which type of cryptanalysis is most likely to succeed against this scheme?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.