
GIAC Open Source Intelligence (GOSI)
Domain 2Objective 3
Network Data and Infrastructure Analysis GOSI Practice Questions (Page 3)
Part of the Target Investigation and Infrastructure Analysis domain, which makes up ~54% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~27–43 in this domain), expect 9–14 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 11–15
- 11
You are profiling a web server that hosts a target application. You need to determine the web server software, its version, and the operating system, but you want to avoid sending malformed packets that could trigger an IDS. Which technique is most appropriate?
Select an answer first - 12
You are analyzing the DNS records of 'example.com' and notice a TXT record containing 'v=spf1 include:_spf.example.net ~all'. What does this indicate?
Select an answer first - 13
An analyst is mapping a target's external infrastructure. They have a single known domain and want to quickly identify additional subdomains and mail servers without sending any traffic to the target. Which approach best meets this requirement?
Select an answer first - 14
An analyst is investigating a suspected phishing campaign. They have a single malicious domain and want to identify all IP addresses that the domain has resolved to over the past year, including historical records. Which data source is most appropriate?
Select an answer first - 15
Which DNS record type is used to perform a reverse DNS lookup, mapping an IP address back to a hostname?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOSI” is a trademark of its owner, used for identification only.