
GIAC Network Forensic Analyst
Domain 2Objective 1
NetFlow Analysis and Attack Visualization GNFA Practice Questions (Page 4)
Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 16–20
- 16
A NetFlow analyst wants to create a visualization that shows the top 10 source IPs by total bytes for a specific time period. Which chart type is most appropriate?
Select an answer first - 17
A network administrator is configuring NetFlow export on a router. The router is connected to a core switch that aggregates traffic from multiple VLANs. The administrator wants to ensure that NetFlow data is collected for all traffic passing through the router, including traffic between VLANs. What is the most important configuration step?
Select an answer first - 18
An analyst is reviewing NetFlow data and notices that a single internal host is communicating with many external IP addresses on port 53 (DNS) but the flow records show unusually large packet sizes for DNS queries. The analyst suspects DNS tunneling. Which NetFlow field would be most useful to confirm this suspicion?
Select an answer first - 19
In the context of network traffic analysis, what is a 'flow' as defined by NetFlow?
Select an answer first - 20
What is a key element of an effective NetFlow analysis report for management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.