
GIAC Network Forensic Analyst
Domain 3Objective 1
Open Source Network Security Proxies GNFA Practice Questions (Page 5)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
6concepts
Questions 21–25
- 21
In a Squid configuration file, which directive is used to define an access control list (ACL) that matches a specific source IP address?
Select an answer first - 22
In HAProxy, which ACL condition is used to match a request based on the URL path?
Select an answer first - 23
A company must block access to a list of websites that changes daily. The list is provided by a third-party threat intelligence service as a text file. The proxy must update its blocklist automatically without manual intervention. Which approach is most efficient and reliable?
Select an answer first - 24
An analyst is investigating a potential data breach. The proxy logs show a large number of outbound requests to an unusual domain. Which of the following log fields would be most useful to determine if data was exfiltrated? Select all that apply.
Select an answer first - 25
A forensic analyst wants to correlate proxy logs with network packet captures. Which field is essential for this correlation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.