Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Network Forensic Analyst

Domain 2Objective 2

Network Protocol Reverse Engineering GNFA Practice Questions (Page 7)

Part of the Network Traffic Analysis and Visualization domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 10–16 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 31–35

  1. 31expert · hard

    An analyst is examining traffic from a compromised host that is exfiltrating data via DNS queries. The subdomains contain hex-encoded data that is then base64-encoded. The analyst needs to extract the original data. The analyst has identified the encoding scheme. What is the correct decoding order?

    Select an answer first
  2. 32application · medium

    An analyst is monitoring a protocol that uses a three-way handshake similar to TCP. The analyst sees a session where the client sends a SYN, the server responds with SYN-ACK, and then the client sends an ACK with a payload. However, the payload contains data that is not expected at this stage of the handshake. What does this indicate?

    Select an answer first
  3. 33application · medium

    An analyst is reconstructing a file transfer session from a pcap. The TCP stream shows out-of-order packets and some retransmissions. The analyst uses Wireshark's 'Follow TCP Stream' feature. What is the primary reason this feature is useful for session reassembly?

    Select an answer first
  4. 34application · medium

    An analyst is examining HTTP traffic that appears to be exfiltrating data. The data is URL-encoded and then base64-encoded. The analyst needs to extract the original data. What is the correct order of decoding steps?

    Select an answer first
  5. 35application · medium

    An analyst is examining DNS traffic that appears to be exfiltrating data. The subdomains contain strings that look like base64-encoded data. The analyst decodes the base64 and gets binary data that appears to be compressed. What is the next step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.