
GIAC Security Operations Certified
Domain 2Objective 2
Protocol Attacks and Analysis GSOC Practice Questions (Page 1)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
Questions 1–5
- 1
A SOC team is investigating a series of alerts: (1) a port scan from IP 203.0.113.5, (2) a successful SSH login to a bastion host from the same IP, (3) an internal port scan from the bastion host, and (4) a large outbound data transfer from a database server. The team has limited analyst time and must prioritize which events to investigate. Which approach would most efficiently confirm whether these events are part of a single attack campaign?
Select an answer first - 2
A SOC analyst is reviewing network traffic and sees a series of HTTP requests to a web server with the following pattern: the first request is a normal GET, followed by a request with a very long URL containing encoded characters, and then a request with a different HTTP method (e.g., PUT) to the same resource. The web server is behind a WAF. Which attack signature is most likely being observed?
Select an answer first - 3
An analyst is investigating a potential TCP session hijack. The analyst has a pcap of the session. Which protocol analysis technique would provide the most direct evidence of session hijacking?
Select an answer first - 4
An analyst is correlating network events and observes the following sequence: (1) a TCP port scan from an external IP, (2) a successful SSH login from the same IP, (3) outbound data transfers to an unknown server. Which multi-step protocol attack does this event correlation most likely indicate?
Select an answer first - 5
A network administrator is troubleshooting a performance issue on a critical server. The server is receiving a high volume of TCP SYN packets, but the connection queue is not filling up, and the server remains responsive. The administrator suspects a SYN flood but is not sure. Which analysis would best determine if this is a SYN flood or a legitimate connection burst?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.