Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 2

Protocol Attacks and Analysis GSOC Practice Questions (Page 7)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
4concepts

Questions 31–33

  1. 31foundation · easy

    A security analyst is correlating events and sees a series of fragmented IP packets that, when reassembled, form a malicious payload targeting a web server. Shortly after, the server logs show an unusual error and a new outbound connection to an IRC server. Which multi-step attack does this correlation best describe?

    Select an answer first
  2. 32application · medium

    A SOC analyst is reviewing DNS logs and notices a domain that resolves to different IP addresses in rapid succession, with each IP located in a different country. The domain is not on any blocklist. Which attack signature does this pattern most likely indicate?

    Select an answer first
  3. 33application · medium

    A network administrator sees a high volume of TCP packets with the RST flag set from a single external IP to various internal hosts. The packets are sent at a steady rate and do not correspond to any established connections. What is the most likely attack?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GSOC

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.