
GIAC Network Forensic Analyst
Domain 2Objective 2
Network Protocol Reverse Engineering GNFA Practice Questions (Page 1)
Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 1–5
- 1
An analyst is modeling a protocol that uses a challenge-response authentication. The client sends a 'CHALLENGE' message, the server responds with a 'CHALLENGE_RESPONSE' that includes a nonce, and the client must then send an 'AUTH' message with a hash of the nonce. If the client sends an 'AUTH' message without receiving a 'CHALLENGE_RESPONSE', what does this indicate?
Select an answer first - 2
An analyst is tasked with reverse engineering an unknown protocol captured in a pcap. The traffic is between two internal hosts on a non-standard port. The analyst notices that the first packet of each session contains a 4-byte value that increments by one for each new session. What is the most likely purpose of this field?
Select an answer first - 3
Which field in an IPv4 header is used to prevent packets from looping indefinitely?
Select an answer first - 4
An analyst is reverse engineering an unknown protocol used by malware. The analyst has captured a large number of sessions and notices that the first packet of each session contains a 4-byte value that is always a multiple of 4. The analyst also notices that the value increases with each session. What is the most likely purpose of this field?
Select an answer first - 5
During an incident response, an analyst captures traffic from a host that communicates with a command-and-control server. The payloads appear to be base64-encoded. After decoding, the analyst sees a string that looks like 'H4sIAAAAAAAAA...'. What is the most likely next step to decode the full payload?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.