Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Network Forensic Analyst

Domain 2Objective 1

NetFlow Analysis and Attack Visualization GNFA Practice Questions (Page 1)

Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 1–5

  1. 1expert · hard

    An analyst is using a NetFlow visualization tool to investigate a potential slow data exfiltration. The tool provides a time-series chart of outbound bytes per hour. The analyst notices a pattern of small, regular spikes every hour, each lasting about 5 minutes. The spikes are not present on weekends. Which interpretation is most likely?

    Select an answer first
  2. 2foundation · easy

    Why is it beneficial to correlate NetFlow data with full packet captures (PCAP) during an investigation?

    Select an answer first
  3. 3expert · hard

    An analyst is reviewing NetFlow data and observes the following patterns: (1) a single internal host sending TCP SYN packets to many external IPs on port 445, (2) a separate internal host sending UDP packets to a single external IP on port 53 with large packet sizes, and (3) a third internal host sending continuous TCP traffic to a known malicious IP on port 443. The analyst must prioritize the incidents. Which pattern is most likely to indicate an active data exfiltration?

    Select an answer first
  4. 4expert · hard

    NetFlow shows a host communicating with an external IP on TCP port 22 (SSH) for 30 minutes, transferring 500 MB. The organization's firewall logs show the connection was allowed, but the host's authentication logs show no successful SSH login. What is the most likely explanation?

    Select an answer first
  5. 5application · easy

    An analyst is reviewing NetFlow records and sees a flow with source IP 192.168.1.10, destination IP 10.0.0.1, source port 50000, destination port 3389, protocol TCP, and 1000 packets with 2 MB total. What is the most likely application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.