Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Network Forensic Analyst

Domain 2Objective 2

Network Protocol Reverse Engineering GNFA Practice Questions (Page 6)

Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 26–30

  1. 26application · medium

    A security analyst is examining a pcap from a compromised host. The traffic shows a TCP session to a remote server on port 443, but the TLS handshake does not complete. Instead, the client sends a single packet with a payload beginning with the bytes 'MZ' followed by binary data, and the server responds with a similar 'MZ' payload. The analyst suspects a custom protocol tunneling over the standard port. Which combination of observations most strongly supports this conclusion?

    Select an answer first
  2. 27expert · hard

    An analyst is monitoring a network that uses a custom protocol over UDP. The protocol normally has a fixed message size of 512 bytes. The analyst observes a series of packets from a single source to a single destination that are all 512 bytes, but the first byte of the payload alternates between 0x01 and 0x02 in a pattern that does not match the expected sequence. The analyst suspects a covert channel. Which of the following is the most likely explanation?

    Select an answer first
  3. 28application · easy

    An analyst is examining a pcap and sees a TCP session to port 22. The payload contains the string 'SSH-2.0-OpenSSH_8.9p1'. Which protocol is this traffic using?

    Select an answer first
  4. 29expert · hard

    An analyst is reassembling a file transfer from a pcap that contains multiple TCP streams. The file was transferred using a custom protocol that splits the file into chunks and sends each chunk in a separate TCP connection. The analyst needs to reconstruct the original file. What is the most effective method?

    Select an answer first
  5. 30foundation · easy

    What is the primary purpose of session reassembly in network forensics?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.