GIAC Network Forensic Analyst (GNFA) Practice Test

169 questions available

Build your confidence for GIAC Network Forensic Analyst (GNFA). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
66 Exam questions
3 hours Time Limit
Your practice
169 Practice questions
2 hours 49 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bank 169 Practice questions checked against the official objectives.
GIAC169 practice questions
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-09-17How we verify

Exam overview and details

GIAC Network Forensic Analyst certification covering packet analysis, network intrusion detection, and digital forensics. Administered by GIAC. Key domains include Common Network Protocols, Encryption and Encoding, NetFlow Analysis and Attack Visualization and Network Architecture. The exam consists of 66 questions over 180 minutes.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Attack Pattern Detection

An analyst observes DNS queries containing very long unique labels (e.g., 60-char hex subdomains) to a single second-level domain at high frequency. Which technique is this most consistent with?

Investigation Workflow

Which characteristic of chain of custody is most often challenged in court?

Attack Pattern Detection

An analyst observes a TCP handshake that completes with a SYN-ACK but the client never sends the third ACK and instead repeatedly sends new SYNs from many random source ports. What attack is most consistent?

Tools

Which Suricata operational mode is appropriate when the deployment should block detected attacks rather than alert only?

NetFlow / Metadata Analysis

Which approach is the most efficient way to find hosts that communicated with a known-bad IP across 90 days of stored telemetry?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

Network forensics provides the definitive, often immutable, evidence of a security incident. While endpoint data can be manipulated, network traffic tells the objective story of what actually traversed the wire. In practical terms, this skill set is indispensable for accurately scoping a breach, identifying the root cause and extent of data loss, attributing activity to specific threats, and providing legally-sound evidence for internal discipline or prosecution. It transforms raw packet data into actionable intelligence, enabling organizations to move from knowing they were compromised to understanding precisely how, when, and by whom.

What this exam covers

01Common Network Protocols

This domain focuses on common network protocols used across various layers to understand communication patterns and protocols during forensic investigations, enabling analysts to evaluate data flows accurately and inspect packet details.

02Encryption and Encoding

This domain covers encryption and encoding techniques applied within network data streams to ensure analysts can properly decode hidden or obscured malicious traffic during security incident investigations and threat analysis activities.

03NetFlow Analysis and Attack Visualization

This domain explores NetFlow analysis methods and attack visualization tools for traffic patterns, enabling analysts to spot anomalies and malicious network behavior quickly across enterprise network infrastructures during active reviews.

04Network Architecture

This domain examines network architecture designs and structural components that affect data flow, helping investigators understand how traffic moves through enterprise environments and where security monitoring points reside.

05Network Protocol Reverse Engineering

This domain deals with network protocol reverse engineering to decode proprietary or unfamiliar formats, empowering analysts to dissect custom network communications during active security incidents and detailed digital investigations.

06Open Source Network Security Proxies

This domain addresses open source network security proxies used in monitoring and intercepting traffic, providing practical skills for real-time traffic inspection and packet capture analysis during security incidents.

07Security Event and Incident Logging

This domain presents security event and incident logging practices for audit trails and monitoring, ensuring that investigators can leverage log data effectively to reconstruct timelines of suspicious activities.

08Wireless Network Analysis

This domain covers wireless network analysis methods to examine wireless traffic and signals, preparing candidates to handle wireless security breaches and anomalies within modern corporate network deployment environments.

Exam Details GNFA | 3 hours

Exam Code GNFA
Vendor GIAC
Time Limit 3 hours
Exam questions 66

Frequently Asked Questions

How much hands-on networking experience do I need before attempting the GNFA?

Is the SANS FOR572 course a mandatory prerequisite for the exam?

What is the exam format, and how is it practical?

Which tools are most critical to master for the exam?

How does GNFA differ from other network-focused certifications like GCIA?