Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 1

Network Traffic Analysis GSOC Practice Questions (Page 1)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
5concepts

Questions 1–5

  1. 1application · medium

    An analyst is inspecting a packet capture and sees an HTTP request with a User-Agent string that is extremely long and contains a series of unusual characters. The request is directed to a web application. What should the analyst do to determine if this is an attack?

    Select an answer first
  2. 2expert · medium

    A company has a policy that all sensitive data must remain within the country's borders. They are considering using a cloud-based SIEM that ingests NetFlow data from their on-premises network. The SIEM provider offers regions in multiple countries. The company's network team is concerned about data sovereignty. Which action best addresses the concern?

    Select an answer first
  3. 3application · medium

    A network administrator is reviewing flow logs and notices that a server in the DMZ is sending a large amount of data to an internal database server on port 1433 (MSSQL) during non-business hours. The data transfer is significantly higher than normal. What is the most likely concern?

    Select an answer first
  4. 4application · medium

    During an incident investigation, an analyst needs to reconstruct the timeline of an attacker's activities on a compromised host. The analyst has NetFlow logs, DNS logs, and a full packet capture from the network perimeter. Which combination of data would provide the most complete timeline?

    Select an answer first
  5. 5application · medium

    A security analyst is investigating a report of a workstation making outbound connections to a known malicious IP. The analyst needs to capture the traffic to and from that specific host without generating a large capture file. The workstation is on a switched network segment, and the analyst has administrative access to the workstation. Which approach should the analyst use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.