
GIAC Network Forensic Analyst
Domain 4Objective 1
Encryption and Encoding GNFA Practice Questions (Page 9)
Part of the Advanced Analysis Techniques domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 41–43
- 41
During an investigation, you find a suspicious string in a log file: `%2Fetc%2Fpasswd`. The string appears to be part of a URL. What is the most likely interpretation?
Select an answer first - 42
A forensic analyst is examining a PCAP and sees traffic on port 22. The analyst wants to confirm that the traffic is encrypted and identify the encryption protocol. Which observation would best confirm that SSH is in use?
Select an answer first - 43
During an investigation, an analyst finds a configuration file that uses a public-key algorithm to sign software updates. Which algorithm is specifically designed for asymmetric operations such as digital signatures?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GNFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.