
GIAC Network Forensic Analyst
Domain 2Objective 1
NetFlow Analysis and Attack Visualization GNFA Practice Questions (Page 5)
Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 21–25
- 21
Which NetFlow analysis technique would be most effective for detecting a distributed port scan?
Select an answer first - 22
In a typical NetFlow deployment, what role does the 'collector' play?
Select an answer first - 23
When interpreting a time series graph of NetFlow data, what does a sudden, sharp spike in traffic to a single destination port indicate?
Select an answer first - 24
What is the primary purpose of NetFlow in network traffic analysis?
Select an answer first - 25
An analyst is using a NetFlow visualization tool to identify hosts that are communicating with a known malicious IP address. The tool provides several visualization options. Which visualization would most efficiently reveal all internal hosts that have flows to the malicious IP?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.