GCIA GIAC Certified Intrusion Analyst Practice Test

299 प्रश्न उपलब्ध

GCIA GIAC Certified Intrusion Analyst के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।

एक नमूना सवाल आज़माएँ
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
सर्टिफिकेशन परीक्षा
106 परीक्षा प्रश्न
4 घंटे समय सीमा
आपका अभ्यास
299 अभ्यास सवाल
4 घंटे 59 मिनट अभ्यास समय
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
पार करने की सीमा 67 इस प्रमाणन के लिए प्रकाशित उत्तीर्णांक।
परीक्षा के विषय जानें GIAC से आधिकारिक उद्देश्य
GIAC299 अभ्यास प्रश्नबैंक 2026-06-17 को अपडेट हुआ
ब्लूप्रिंट सत्यापितGIAC official objectives के साथ जाँचा गयामेटाडेटा सत्यापित 2026-06-11हम कैसे सत्यापित करते हैं

परीक्षा का परिचय और विवरण

The GIAC Certified Intrusion Analyst (GCIA) certification is a premier, industry-recognized credential validating an individual's advanced skills in network security monitoring, intrusion detection, and incident response. Administered by the Global Information Assurance Certification (GIAC), a SANS Institute affiliate, the GCIA focuses on the deep technical analysis of network traffic to identify, respond to, and defend against sophisticated cyber threats. Earning the GCIA demonstrates mastery of core competencies including the creation and tuning of IDS/IPS signatures (particularly Snort rules), comprehensive TCP/IP protocol analysis, network forensics, and log analysis using tools like Wireshark. It signifies that the holder can move beyond alert monitoring to perform proactive threat hunting and detailed incident reconstruction. This certification is highly valued by employers in Security Operations Centers (SOCs), Computer Security Incident Response Teams (CSIRTs), and threat intelligence units, as it proves the practical ability to defend critical network infrastructure.

नमूना प्रश्न

अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।

Network Forensics and Traffic Analysis

During GCIA packet-analysis review, Zeek conn.log shows a workstation making HTTPS connections to one new IP every 61 seconds with 900 bytes out and 700 bytes back. What is the BEST interpretation or next analyst action?

SANS GCIA - GIAC Certified Intrusion Analyst

While performing traffic analysis with Wireshark on a potentially compromised workstation, you observe several TCP/IP protocol anomalies. Which observations would be considered valid indicators of suspicious network behavior warranting further investigation? (Select all that apply)

Concepts of TCP/IP and the Link Layer

During GCIA packet-analysis review, A capture shows IPv4 protocol number 1 in the header after Ethernet decoding. What is the BEST interpretation or next analyst action?

TCP

During GCIA packet-analysis review, A SYN includes MSS, SACK permitted, window scale, and timestamp options in an unusual order for the claimed OS. What is the BEST interpretation or next analyst action?

Concepts of TCP/IP and the Link Layer

During GCIA packet-analysis review, A span port misses short microbursts even though average utilization is low. What is the BEST interpretation or next analyst action?

करियर के अवसर और वेतन

मध्य वेतन: $129,180US मार्केट– Information Security Analysts

स्रोत: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।

इस परीक्षा में क्या शामिल है

01Concepts of TCP/IP and the Link Layer

विषय

  • Concepts of TCP/IP and the Link Layer

सीखने के उद्देश्य

  • Concepts of TCP/IP and the Link Layer: Demonstrate understanding of the TCP/IP communications model and link layer operations

02Fragmentation

विषय

  • Fragmentation

सीखने के उद्देश्य

  • Fragmentation: Demonstrate understanding of how fragmentation works, and how to identify fragmentation and fragmentation-based attacks in packet captures

03Fundamentals of Traffic Analysis and Application Protocols

विषय

  • Application Protocols

सीखने के उद्देश्य

  • Application Protocols: Demonstrate knowledge and skill relating to application layer protocol dissection and analysis

04IP Headers

विषय

  • IP Headers

सीखने के उद्देश्य

  • IP Headers: Demonstrate the ability to dissect IP packet headers and analyze them for normal and anomalous values that may point to security issues

05IPv6

विषय

  • IPv6

सीखने के उद्देश्य

  • IPv6: Demonstrate knowledge of IPv6 and how it differs from IPv4

06Network Traffic Forensics and Monitoring

विषय

  • Network Forensics and Traffic Analysis

सीखने के उद्देश्य

  • Network Forensics and Traffic Analysis: Demonstrate competence in analyzing data from multiple sources (e.g., full packet capture, netflow, log files) to identify normal and malicious behaviors

07Open-Source Intrusion Detection Systems (IDS): Snort and Zeek

विषय

  • IDS Fundamentals and Network Architecture
  • Intrusion Detection System Rules

सीखने के उद्देश्य

  • IDS Fundamentals and Network Architecture: Demonstrate knowledge of fundamental IDS concepts, such as network architecture options and benefits/weaknesses of common IDS systems
  • Intrusion Detection System Rules: Create effective IDS rules to detect varied types of malicious activity

08Packet Engineering

विषय

  • Packet Engineering

सीखने के उद्देश्य

  • Packet Engineering: Demonstrate knowledge relating to packet crafting and manipulation

09SiLK and Other Traffic Analysis Tools

विषय

  • SiLK and Other Traffic Analysis Tools

सीखने के उद्देश्य

  • SiLK and Other Traffic Analysis Tools: Demonstrate an understanding of SiLK and other tools to perform network traffic and flow analysis

10TCP

विषय

  • TCP

सीखने के उद्देश्य

  • TCP: Demonstrate understanding of the TCP protocol and the ability to discern between typical and anomalous behavior

11Tcpdump Filters

विषय

  • Tcpdump Filters

सीखने के उद्देश्य

  • Tcpdump Filters: Demonstrate ability to craft tcpdump filters that match on given criteria

12UDP and ICMP

विषय

  • UDP and ICMP

सीखने के उद्देश्य

  • UDP and ICMP: Demonstrate understanding of the UDP and ICMP protocols and the ability to discern between typical and anomalous behavior

13Wireshark Fundamentals

विषय

  • Wireshark Fundamentals

सीखने के उद्देश्य

  • Wireshark Fundamentals: Demonstrate ability to use Wireshark to analyze typical and malicious network traffic

परीक्षा विवरण GCIA | $949 USD | 4 घंटे

परीक्षा कोड GCIA
विक्रेता GIAC
परीक्षा शुल्क $949 USD
उत्तीर्ण अंक 67
समय सीमा 4 घंटे
परीक्षा प्रश्न 106
प्रश्न प्रकार मल्टिपल चॉइस (100%)
पुनः परीक्षा नीति Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
परीक्षा प्रारूप Multiple Choice
ऑनलाइन निगरानी उपलब्ध

अक्सर पूछे जाने वाले प्रश्न

GCIA प्रमाणपत्र धारक के लिए प्राथमिक नौकरी की भूमिकाएँ क्या हैं?

GCIA, Security+ या GSEC जैसी अधिक प्रारंभिक स्तर की प्रमाणपत्रों से कैसे भिन्न है?

GCIA परीक्षा के लिए अनुशंसित तैयारी का मार्ग क्या है?

क्या GCIA परीक्षा व्यावहारिक, बहुविकल्पीय, या संयोजन है?

GCIA प्रमाणपत्र की वैधता कितनी है, और नवीनीकरण की आवश्यकताएँ क्या हैं?