GCIA GIAC Certified Intrusion Analyst Practice Test

299 questions available

Build your confidence for GCIA GIAC Certified Intrusion Analyst. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
106 Exam questions
4 hours Time Limit
Your practice
299 Practice questions
4 hours 59 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 67 Published passing score for this certification.
Explore exam topics Official objectives from GIAC
GIAC299 practice questionsBank updated 2026-06-17
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-06-11How we verify

Exam overview and details

The GIAC Certified Intrusion Analyst (GCIA) certification is a premier, industry-recognized credential validating an individual's advanced skills in network security monitoring, intrusion detection, and incident response. Administered by the Global Information Assurance Certification (GIAC), a SANS Institute affiliate, the GCIA focuses on the deep technical analysis of network traffic to identify, respond to, and defend against sophisticated cyber threats. Earning the GCIA demonstrates mastery of core competencies including the creation and tuning of IDS/IPS signatures (particularly Snort rules), comprehensive TCP/IP protocol analysis, network forensics, and log analysis using tools like Wireshark. It signifies that the holder can move beyond alert monitoring to perform proactive threat hunting and detailed incident reconstruction. This certification is highly valued by employers in Security Operations Centers (SOCs), Computer Security Incident Response Teams (CSIRTs), and threat intelligence units, as it proves the practical ability to defend critical network infrastructure.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Network Forensics and Traffic Analysis

During GCIA packet-analysis review, Zeek conn.log shows a workstation making HTTPS connections to one new IP every 61 seconds with 900 bytes out and 700 bytes back. What is the BEST interpretation or next analyst action?

SANS GCIA - GIAC Certified Intrusion Analyst

While performing traffic analysis with Wireshark on a potentially compromised workstation, you observe several TCP/IP protocol anomalies. Which observations would be considered valid indicators of suspicious network behavior warranting further investigation? (Select all that apply)

Concepts of TCP/IP and the Link Layer

During GCIA packet-analysis review, A capture shows IPv4 protocol number 1 in the header after Ethernet decoding. What is the BEST interpretation or next analyst action?

TCP

During GCIA packet-analysis review, A SYN includes MSS, SACK permitted, window scale, and timestamp options in an unusual order for the claimed OS. What is the BEST interpretation or next analyst action?

Concepts of TCP/IP and the Link Layer

During GCIA packet-analysis review, A span port misses short microbursts even though average utilization is low. What is the BEST interpretation or next analyst action?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

Achieving the GCIA certification is a significant career differentiator in the cybersecurity field. It provides tangible proof of high-demand, hands-on technical skills that are critical for roles such as Intrusion Analyst, Network Forensic Analyst, and Threat Hunter. The certification is recognized globally by government agencies, military organizations, and leading corporations as a benchmark for intrusion analysis expertise. Holding a GCIA not only validates your technical proficiency but also signals a deep commitment to the cybersecurity profession, directly enhancing your credibility, marketability, and potential for career advancement and increased compensation in a competitive job market.

What this exam covers

01Concepts of TCP/IP and the Link Layer

Topics

  • Concepts of TCP/IP and the Link Layer

Learning objectives

  • Concepts of TCP/IP and the Link Layer: Demonstrate understanding of the TCP/IP communications model and link layer operations

02Fragmentation

Topics

  • Fragmentation

Learning objectives

  • Fragmentation: Demonstrate understanding of how fragmentation works, and how to identify fragmentation and fragmentation-based attacks in packet captures

03Fundamentals of Traffic Analysis and Application Protocols

Topics

  • Application Protocols

Learning objectives

  • Application Protocols: Demonstrate knowledge and skill relating to application layer protocol dissection and analysis

04IP Headers

Topics

  • IP Headers

Learning objectives

  • IP Headers: Demonstrate the ability to dissect IP packet headers and analyze them for normal and anomalous values that may point to security issues

05IPv6

Topics

  • IPv6

Learning objectives

  • IPv6: Demonstrate knowledge of IPv6 and how it differs from IPv4

06Network Traffic Forensics and Monitoring

Topics

  • Network Forensics and Traffic Analysis

Learning objectives

  • Network Forensics and Traffic Analysis: Demonstrate competence in analyzing data from multiple sources (e.g., full packet capture, netflow, log files) to identify normal and malicious behaviors

07Open-Source Intrusion Detection Systems (IDS): Snort and Zeek

Topics

  • IDS Fundamentals and Network Architecture
  • Intrusion Detection System Rules

Learning objectives

  • IDS Fundamentals and Network Architecture: Demonstrate knowledge of fundamental IDS concepts, such as network architecture options and benefits/weaknesses of common IDS systems
  • Intrusion Detection System Rules: Create effective IDS rules to detect varied types of malicious activity

08Packet Engineering

Topics

  • Packet Engineering

Learning objectives

  • Packet Engineering: Demonstrate knowledge relating to packet crafting and manipulation

09SiLK and Other Traffic Analysis Tools

Topics

  • SiLK and Other Traffic Analysis Tools

Learning objectives

  • SiLK and Other Traffic Analysis Tools: Demonstrate an understanding of SiLK and other tools to perform network traffic and flow analysis

10TCP

Topics

  • TCP

Learning objectives

  • TCP: Demonstrate understanding of the TCP protocol and the ability to discern between typical and anomalous behavior

11Tcpdump Filters

Topics

  • Tcpdump Filters

Learning objectives

  • Tcpdump Filters: Demonstrate ability to craft tcpdump filters that match on given criteria

12UDP and ICMP

Topics

  • UDP and ICMP

Learning objectives

  • UDP and ICMP: Demonstrate understanding of the UDP and ICMP protocols and the ability to discern between typical and anomalous behavior

13Wireshark Fundamentals

Topics

  • Wireshark Fundamentals

Learning objectives

  • Wireshark Fundamentals: Demonstrate ability to use Wireshark to analyze typical and malicious network traffic

Exam Details GCIA | $949 USD | 4 hours

Exam Code GCIA
Vendor GIAC
Exam Cost $949 USD
Passing Score 67
Time Limit 4 hours
Exam questions 106
Question Types Multiple choice (100%)
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

What are the primary job roles for someone holding a GCIA certification?

How does the GCIA differ from more entry-level certifications like Security+ or GSEC?

What is the recommended preparation path for the GCIA exam?

Is the GCIA exam practical, multiple-choice, or a combination?

How long is the GCIA certification valid, and what are the renewal requirements?