Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Network Forensic Analyst

Domain 2Objective 2

Network Protocol Reverse Engineering GNFA Practice Questions (Page 2)

Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 6–10

  1. 6application · medium

    A forensic analyst is reconstructing a file transfer from a pcap. The TCP stream shows packets arriving out of order and with retransmissions. The analyst uses Wireshark's 'Follow TCP Stream' feature. What is the primary reason this feature is effective for this task?

    Select an answer first
  2. 7application · easy

    An analyst is dissecting a packet from a custom protocol. The first 2 bytes are 0x1234, the next 2 bytes are 0x0005, and the remaining bytes are the payload. The analyst knows that the first field is a magic number and the second field is a length field. If the length field is in network byte order (big-endian), what is the length of the payload?

    Select an answer first
  3. 8expert · hard

    A security analyst is reviewing traffic from a network that uses a proprietary protocol on TCP port 5000. The analyst sees a session on port 5000 that uses a standard HTTP GET request. The analyst also sees another session on port 5000 that uses a custom binary protocol with a magic number. What should the analyst conclude?

    Select an answer first
  4. 9application · medium

    A security analyst is reviewing traffic from a network that is known to use a proprietary protocol on TCP port 5000. The analyst sees a session on port 5000 that uses a standard HTTP GET request. What should the analyst conclude?

    Select an answer first
  5. 10expert · hard

    An analyst is monitoring a network that uses a custom protocol over TCP. The protocol normally sends a 'REQUEST' message and waits for a 'RESPONSE' message. The analyst observes a session where the client sends a 'REQUEST', the server sends a 'RESPONSE', and then the client sends another 'REQUEST' without waiting for a response to the first. Which of the following is the most likely explanation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.