
GIAC Security Operations Certified
Domain 2Objective 1
Network Traffic Analysis GSOC Practice Questions (Page 7)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
5concepts
Questions 31–34
- 31
Which of the following is a common indicator of an anomaly in network traffic flow analysis?
Select an answer first - 32
An analyst needs to capture traffic on a high-traffic network segment to investigate a possible malware infection. The analyst has limited disk space and needs to capture only the relevant traffic. The malware is known to communicate over HTTP and DNS. Which capture strategy is most appropriate?
Select an answer first - 33
A security analyst is reviewing NetFlow data and notices a large volume of data being transferred from an internal database server to an external IP address during off-hours. The transfer is over port 443. The analyst needs to determine if this is a data exfiltration. Which additional data source would be most useful to confirm the nature of the transfer?
Select an answer first - 34
A security analyst is reviewing NetFlow data and notices that a single internal host is communicating with multiple external IP addresses on port 22 (SSH) simultaneously. The host is a user workstation. What is the most likely explanation?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GSOC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.