
GIAC Security Operations Certified
Domain 2Objective 2
Protocol Attacks and Analysis GSOC Practice Questions (Page 2)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
Questions 6–10
- 6
An analyst sees a series of alerts: first, a port scan from an external IP; then, a successful SSH login from the same IP to a jump host; and finally, lateral movement to an internal database server. Which event correlation technique would best confirm that these events are part of a single multi-step attack?
Select an answer first - 7
An organization experiences the following sequence of events: (1) a single internal host sends a TCP SYN to an external server; (2) the server responds with SYN-ACK; (3) the internal host sends an ACK; (4) the internal host sends a series of TCP packets with the PSH flag and a payload that matches a known exploit signature; (5) the server responds with a 200 OK; (6) the internal host sends a TCP RST. The analyst must determine if this is an attack. Which additional evidence would most strongly indicate a false positive?
Select an answer first - 8
An organization's SIEM shows a spike in outbound DNS queries from a single workstation to a rarely-used internal DNS server, each query having a long subdomain. The workstation also shows a large amount of data sent to an external IP over HTTPS. Which correlation would most likely identify the attack?
Select an answer first - 9
An analyst is examining a pcap that shows a TCP connection with the following characteristics: the initial packet has the SYN and ACK flags set, the sequence numbers are random, and the window size is 0. The connection is to a database server on port 1433. The analyst must determine if this is a legitimate connection or an attack. Which analysis would be most conclusive?
Select an answer first - 10
A security analyst is reviewing a pcap and sees a TCP packet with the ACK flag set, an acknowledgment number that is not in the expected range, and a payload that contains a known exploit string. The packet is part of an established connection. What should the analyst do to determine if this is a real attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.