
GIAC Security Operations Certified
Domain 2Objective 1
Network Traffic Analysis GSOC Practice Questions (Page 5)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
5concepts
Questions 21–25
- 21
An analyst is examining a pcap and sees a TCP handshake with the SYN flag, followed by a PSH-ACK packet containing data, and then a FIN-ACK. The data in the PSH-ACK packet is a single HTTP GET request. The analyst notices that the source IP is a known scanner. What does this pattern indicate?
Select an answer first - 22
What is the primary purpose of packet inspection in network security?
Select an answer first - 23
During an incident response, an analyst has a pcap file that contains traffic from a compromised host. The analyst needs to determine the exact time when the attacker first accessed the host. The pcap contains traffic from multiple days. What is the most efficient way to find the first packet from the attacker's IP address?
Select an answer first - 24
An analyst is investigating a suspected data exfiltration and has a pcap file. The analyst notices that the traffic is encrypted (TLS). The analyst has access to the private key of the server that the traffic is destined to. What is the best way to decrypt and analyze the traffic?
Select an answer first - 25
An analyst is inspecting a packet capture and sees a TCP connection to a server on port 3389 (RDP). The connection is from an external IP and the analyst notices that the RDP traffic is encrypted. The analyst suspects an attempted RDP brute force. Which evidence in the capture would best support this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.