Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 2

Protocol Attacks and Analysis GSOC Practice Questions (Page 6)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
4concepts

Questions 26–30

  1. 26application · medium

    A network analyst sees a series of UDP packets from an internal host to a remote server with the same source and destination ports, and the payload contains a repeated pattern that matches a known DNS amplification signature. The packets are sent at a steady rate. What should the analyst do first to confirm the attack?

    Select an answer first
  2. 27application · medium

    An analyst is examining a pcap file and sees a TCP stream with the ACK flag set on every packet, including the initial packet of the connection. The sequence numbers are not incrementing as expected. Which protocol analysis technique would best confirm whether this is a legitimate TCP session or a crafted attack?

    Select an answer first
  3. 28application · medium

    A SOC analyst is reviewing HTTP traffic and sees a series of requests to a web application with URLs containing long strings of percent-encoded characters. The application logs show some requests returned a 500 error. Which protocol attack is most likely being attempted?

    Select an answer first
  4. 29foundation · easy

    A security analyst observes a TCP handshake where the client sends a SYN packet, the server responds with SYN-ACK, and the client never sends the final ACK. The client repeats this behavior with many different destination ports on the same host. Which type of protocol attack does this traffic pattern most directly indicate?

    Select an answer first
  5. 30expert · hard

    A SOC analyst is correlating events from multiple sources: firewall logs show a spike in outbound connections to a known malicious IP, DNS logs show a query for a domain that resolves to that IP, and endpoint logs show a process making HTTP requests to the same domain. The analyst must determine the root cause and scope of the compromise. Which correlation would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.