
GIAC Network Forensic Analyst
Domain 2Objective 2
Network Protocol Reverse Engineering GNFA Practice Questions (Page 6)
Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 26–30
- 26
A security analyst is examining a pcap from a compromised host. The traffic shows a TCP session to a remote server on port 443, but the TLS handshake does not complete. Instead, the client sends a single packet with a payload beginning with the bytes 'MZ' followed by binary data, and the server responds with a similar 'MZ' payload. The analyst suspects a custom protocol tunneling over the standard port. Which combination of observations most strongly supports this conclusion?
Select an answer first - 27
An analyst is monitoring a network that uses a custom protocol over UDP. The protocol normally has a fixed message size of 512 bytes. The analyst observes a series of packets from a single source to a single destination that are all 512 bytes, but the first byte of the payload alternates between 0x01 and 0x02 in a pattern that does not match the expected sequence. The analyst suspects a covert channel. Which of the following is the most likely explanation?
Select an answer first - 28
An analyst is examining a pcap and sees a TCP session to port 22. The payload contains the string 'SSH-2.0-OpenSSH_8.9p1'. Which protocol is this traffic using?
Select an answer first - 29
An analyst is reassembling a file transfer from a pcap that contains multiple TCP streams. The file was transferred using a custom protocol that splits the file into chunks and sends each chunk in a separate TCP connection. The analyst needs to reconstruct the original file. What is the most effective method?
Select an answer first - 30
What is the primary purpose of session reassembly in network forensics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.