
GIAC Network Forensic Analyst
Domain 2Objective 1
NetFlow Analysis and Attack Visualization GNFA Practice Questions (Page 2)
Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 6–10
- 6
An analyst needs to report a confirmed port scan to the incident response team. Which information is most important to include in the report?
Select an answer first - 7
What is the primary purpose of sampling in NetFlow export?
Select an answer first - 8
What type of visualization is often used to represent communication paths between hosts in a network?
Select an answer first - 9
When presenting NetFlow analysis findings to non-technical stakeholders, what is the most effective approach?
Select an answer first - 10
Why are timestamps significant in NetFlow records?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.