
GIAC Network Forensic Analyst
Domain 2Objective 1
NetFlow Analysis and Attack Visualization GNFA Practice Questions (Page 10)
Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 46–50
- 46
An analyst is using a NetFlow visualization tool to investigate a potential DDoS attack. The tool can generate various charts. Which visualization would most quickly reveal the scale and source distribution of the attack?
Select an answer first - 47
Which additional data source would be most useful to confirm whether a NetFlow-detected spike in outbound traffic is malicious?
Select an answer first - 48
Which NetFlow metric pattern is most indicative of a DDoS (Distributed Denial of Service) attack?
Select an answer first - 49
A network analyst needs to present NetFlow data to management to show a gradual increase in outbound traffic over the past month, likely indicating data exfiltration. Which type of visualization would best communicate this trend over time?
Select an answer first - 50
A NetFlow analyst notices a sudden increase in flows from many external IPs to a single internal server on TCP port 443, each flow with 1-2 packets and no response flows. What does this pattern most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GNFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.