An unhandled error has occurred. Reload X

GIAC Network Forensic Analyst (GNFA) Practice Test

169 preguntas disponibles

GIAC Network Forensic Analyst certification covering packet analysis, network intrusion detection, and digital forensics. Administered by GIAC. Key domains include Common Network Protocols, Encryption and Encoding, NetFlow Analysis and Attack Visualization and Network Architecture.

Oportunidades profesionales y salario
Nivel inicial $62,538 - $94,538
Nivel medio $92,538 - $137,538
Nivel senior $127,538 - $187,538
growing mercado
Por qué esta certificación abre puertas

Network forensics provides the definitive, often immutable, evidence of a security incident. While endpoint data can be manipulated, network traffic tells the objective story of what actually traversed the wire. In practical terms, this skill set is indispensable for accurately scoping a breach, identifying the root cause and extent of data loss, attributing activity to specific threats, and providing legally-sound evidence for internal discipline or prosecution. It transforms raw packet data into actionable intelligence, enabling organizations to move from knowing they were compromised to understanding precisely how, when, and by whom.

Plan de Estudio
01Common Network ProtocolsBehavior, security risks, and controls of common network protocols
02Encryption and EncodingTechniques to encode and encrypt network traffic, Common attacks on encryption and encoding controls
03NetFlow Analysis and Attack VisualizationUse NetFlow data to identify network attacks
04Network ArchitectureDesign and deploy a network with diverse transmission and collection technologies
05Network Protocol Reverse EngineeringAnalyze diverse protocols and data traversing a network
06Open Source Network Security ProxiesArchitecture, deployment, benefits, and weaknesses of network security proxies, Common log formats and data flow
07Security Event and Incident LoggingDiverse log formats and protocols, Configure and deploy logging aggregators and collection devices
08Wireless Network AnalysisIdentify and control risks of wireless technologies, protocols, and infrastructure
Detalles del Examen GIAC-GNFA
Código del Examen GIAC-GNFA
Proveedor GIAC
Preguntas Frecuentes

How much hands-on networking experience do I need before attempting the GNFA?

Substantial practical experience is strongly recommended. You should be thoroughly comfortable with TCP/IP fundamentals, reading and interpreting packet headers in Wireshark/TShark, and understanding common network architectures. Experience from roles in network administration, security operations, or incident response is highly beneficial. The exam tests applied skills, not just theoretical knowledge.

Is the SANS FOR572 course a mandatory prerequisite for the exam?

While not a formal requirement, the FOR572: Advanced Network Forensics and Analysis course is the official training vehicle for the GNFA. The exam blueprint aligns directly with its content. Self-study is possible for exceptionally experienced practitioners, but the course provides the structured curriculum, curated evidence files, and expert instruction that most candidates find essential for success.

What is the exam format, and how is it practical?

The GNFA is a proctored, 2-hour exam consisting of 65-75 questions. A significant portion involves performance-based questions (PBQs) where you must analyze provided evidence files (e.g., PCAPs, logs) within a virtual lab environment to answer specific investigative questions. This format directly tests your ability to perform tasks, not just recall information.

Which tools are most critical to master for the exam?

Wireshark (and its command-line counterpart TShark) is the cornerstone tool. You must also be proficient with tools for NetFlow analysis (like SiLK or NFDUMP), log analysis, and timeline creation. The exam focuses on the analytical process and tool-agnostic concepts, but fluency in these primary applications is necessary to complete the practical tasks efficiently.

How does GNFA differ from other network-focused certifications like GCIA?

The GIAC Certified Intrusion Analyst (GCIA) focuses on network monitoring, intrusion detection, and the real-time signature/ anomaly-based analysis of traffic to identify attacks. The GNFA focuses on post-incident forensics: the in-depth examination of captured network evidence to reconstruct events, prove malicious activity, and determine scope and impact. GCIA is about finding the needle in the haystack; GNFA is about dissecting the needle to understand its entire history.

Reseñas y Calificaciones
Aún sin reseñas

¡Sé el primero en reseñar este examen y ayuda a otros estudiantes!


Comparte Tu Experiencia