
GIAC Security Operations Certified
Domain 2Objective 2
Protocol Attacks and Analysis GSOC Practice Questions (Page 5)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
Questions 21–25
- 21
A security team is monitoring a web application and sees a series of HTTP requests with the following pattern: the first request is a normal GET, followed by several requests with the same session ID but different User-Agent strings, and then a request with a very long Cookie header. The application is behind a load balancer. Which attack signature is most likely being observed?
Select an answer first - 22
A network defender is analyzing a pcap and notices a series of ICMP Echo Request packets with payloads that contain repeating patterns of 'A' characters. The source IP is spoofed. Which attack signature does this pattern most strongly suggest?
Select an answer first - 23
A SOC analyst notices a large volume of UDP packets from many different source IPs to a single destination IP on port 53. The packets are small, but the responses are large. The destination IP is not a DNS server. Which attack is most likely occurring?
Select an answer first - 24
An analyst is examining a pcap file and sees a series of TCP segments with the URG flag set and a non-zero urgent pointer. The payload contains repeated bytes that resemble a known exploit string. Which protocol analysis technique would best confirm whether this is a real attack or a false positive?
Select an answer first - 25
An analyst is investigating a series of events: (1) a single internal host sends a TCP SYN to an external server; (2) the server responds with SYN-ACK; (3) the internal host sends an ACK; (4) then the internal host sends a series of TCP packets with the PSH flag and a payload that matches a known exploit signature; (5) the server responds with a 200 OK. The analyst must determine if this is an attack. Which additional evidence would most strongly indicate an attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.