
GIAC Network Forensic Analyst
Domain 4Objective 1
Encryption and Encoding GNFA Practice Questions (Page 8)
Part of the Advanced Analysis Techniques domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 36–40
- 36
In a packet capture, an analyst sees the following URI: '/search?q=hello%20world'. What does '%20' represent?
Select an answer first - 37
A security team is designing a solution to securely transfer files between two servers over the internet. They need to ensure confidentiality and integrity of the data in transit. They also want to use a single shared secret for simplicity. Which approach best meets their requirements?
Select an answer first - 38
A security team is designing a system where a server must authenticate itself to clients without exposing its private key. Which approach best achieves this?
Select an answer first - 39
Which statement best distinguishes encoding from encryption in the context of network data analysis?
Select an answer first - 40
A forensic analyst is analyzing a PCAP and finds that a client and server are using a protocol that uses a public/private key pair for key exchange and a symmetric cipher for data encryption. Which combination of algorithms is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.