Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Network Forensic Analyst

Domain 2Objective 2

Network Protocol Reverse Engineering GNFA Practice Questions (Page 1)

Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 1–5

  1. 1application · medium

    An analyst is modeling a protocol that uses a challenge-response authentication. The client sends a 'CHALLENGE' message, the server responds with a 'CHALLENGE_RESPONSE' that includes a nonce, and the client must then send an 'AUTH' message with a hash of the nonce. If the client sends an 'AUTH' message without receiving a 'CHALLENGE_RESPONSE', what does this indicate?

    Select an answer first
  2. 2application · medium

    An analyst is tasked with reverse engineering an unknown protocol captured in a pcap. The traffic is between two internal hosts on a non-standard port. The analyst notices that the first packet of each session contains a 4-byte value that increments by one for each new session. What is the most likely purpose of this field?

    Select an answer first
  3. 3foundation · easy

    Which field in an IPv4 header is used to prevent packets from looping indefinitely?

    Select an answer first
  4. 4expert · hard

    An analyst is reverse engineering an unknown protocol used by malware. The analyst has captured a large number of sessions and notices that the first packet of each session contains a 4-byte value that is always a multiple of 4. The analyst also notices that the value increases with each session. What is the most likely purpose of this field?

    Select an answer first
  5. 5application · medium

    During an incident response, an analyst captures traffic from a host that communicates with a command-and-control server. The payloads appear to be base64-encoded. After decoding, the analyst sees a string that looks like 'H4sIAAAAAAAAA...'. What is the most likely next step to decode the full payload?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.