Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Network Forensic Analyst

Domain 4Objective 1

Encryption and Encoding GNFA Practice Questions (Page 9)

Part of the Advanced Analysis Techniques domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 41–43

  1. 41application · easy

    During an investigation, you find a suspicious string in a log file: `%2Fetc%2Fpasswd`. The string appears to be part of a URL. What is the most likely interpretation?

    Select an answer first
  2. 42application · easy

    A forensic analyst is examining a PCAP and sees traffic on port 22. The analyst wants to confirm that the traffic is encrypted and identify the encryption protocol. Which observation would best confirm that SSH is in use?

    Select an answer first
  3. 43foundation · easy

    During an investigation, an analyst finds a configuration file that uses a public-key algorithm to sign software updates. Which algorithm is specifically designed for asymmetric operations such as digital signatures?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GNFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.