GIAC Network Forensic Analyst (GNFA) Practice Test
Gana confianza para GIAC Network Forensic Analyst (GNFA). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.
Probar una preguntaDescripción y detalles del examen
GIAC Network Forensic Analyst certification covering packet analysis, network intrusion detection, and digital forensics. Administered by GIAC. Key domains include Common Network Protocols, Encryption and Encoding, NetFlow Analysis and Attack Visualization and Network Architecture. The exam consists of 66 questions over 180 minutes.
Preguntas de Muestra
Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.
An analyst observes DNS queries containing very long unique labels (e.g., 60-char hex subdomains) to a single second-level domain at high frequency. Which technique is this most consistent with?
Which characteristic of chain of custody is most often challenged in court?
An analyst observes a TCP handshake that completes with a SYN-ACK but the client never sends the third ACK and instead repeatedly sends new SYNs from many random source ports. What attack is most consistent?
Which Suricata operational mode is appropriate when the deployment should block detected attacks rather than alert only?
Which approach is the most efficient way to find hosts that communicated with a known-bad IP across 90 days of stored telemetry?
Oportunidades profesionales y salario
Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.
Qué temas cubre este examen
01Common Network Protocols
This domain focuses on common network protocols used across various layers to understand communication patterns and protocols during forensic investigations, enabling analysts to evaluate data flows accurately and inspect packet details.
02Encryption and Encoding
This domain covers encryption and encoding techniques applied within network data streams to ensure analysts can properly decode hidden or obscured malicious traffic during security incident investigations and threat analysis activities.
03NetFlow Analysis and Attack Visualization
This domain explores NetFlow analysis methods and attack visualization tools for traffic patterns, enabling analysts to spot anomalies and malicious network behavior quickly across enterprise network infrastructures during active reviews.
04Network Architecture
This domain examines network architecture designs and structural components that affect data flow, helping investigators understand how traffic moves through enterprise environments and where security monitoring points reside.
05Network Protocol Reverse Engineering
This domain deals with network protocol reverse engineering to decode proprietary or unfamiliar formats, empowering analysts to dissect custom network communications during active security incidents and detailed digital investigations.
06Open Source Network Security Proxies
This domain addresses open source network security proxies used in monitoring and intercepting traffic, providing practical skills for real-time traffic inspection and packet capture analysis during security incidents.
07Security Event and Incident Logging
This domain presents security event and incident logging practices for audit trails and monitoring, ensuring that investigators can leverage log data effectively to reconstruct timelines of suspicious activities.
08Wireless Network Analysis
This domain covers wireless network analysis methods to examine wireless traffic and signals, preparing candidates to handle wireless security breaches and anomalies within modern corporate network deployment environments.