
GIAC Security Operations Certified
Domain 2Objective 2
Protocol Attacks and Analysis GSOC Practice Questions (Page 7)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
Questions 31–33
- 31
A security analyst is correlating events and sees a series of fragmented IP packets that, when reassembled, form a malicious payload targeting a web server. Shortly after, the server logs show an unusual error and a new outbound connection to an IRC server. Which multi-step attack does this correlation best describe?
Select an answer first - 32
A SOC analyst is reviewing DNS logs and notices a domain that resolves to different IP addresses in rapid succession, with each IP located in a different country. The domain is not on any blocklist. Which attack signature does this pattern most likely indicate?
Select an answer first - 33
A network administrator sees a high volume of TCP packets with the RST flag set from a single external IP to various internal hosts. The packets are sent at a steady rate and do not correspond to any established connections. What is the most likely attack?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GSOC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.