Free GCIA sample questions
Real questions from the GIAC Certified Intrusion Analyst practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 4 of 9 free sample questions.
A financial services company has deployed a new NIDS solution at its internet edge. The network architecture uses asymmetric routing for outbound traffic, meaning that traffic leaving the organization may exit through one of two different ISP links, but all return traffic for a given session is guaranteed to arrive via the same link it departed from. The NIDS is placed inline on the primary ISP link but only has a TAP on the secondary link. Analysts are reporting a high volume of alerts for TCP sessions that appear to be incomplete or have anomalous state transitions, but upon investigation, the traffic is benign. The security team is also concerned about the NIDS's ability to reassemble fragmented packets and maintain state for application-layer protocols like HTTP/2, which rely on a single, long-lived TCP connection. The primary goal is to achieve reliable threat detection without impacting the performance of the high-speed links. Which of the following is the most effective strategy to address the false positives and ensure reliable detection?
An analyst is examining an IPv6 packet capture and finds a packet with a chain of extension headers. The goal is to determine if this packet is being used to bypass a security device that only inspects a limited number of headers. Which extension header, if placed before the Destination Options header, would be the most likely to contain the *actual* final destination address that a compromised host would process? graph TD IPv6_Base["IPv6 Base Header Next Header: Hop-by-Hop"] --> HopByHop["Hop-by-Hop Options Next Header: Routing"] HopByHop --> Routing["Routing Header Next Header: Fragment"] Routing --> Fragment["Fragment Header Next Header: Destination Options"] Fragment --> DestOpts["Destination Options Next Header: TCP"] DestOpts --> TCP_Header["TCP Header & Payload"]
True or False: An anomaly-based Intrusion Detection System (IDS) can potentially detect novel, never-before-seen attacks, but it is also more prone to false positives than a signature-based IDS.
5 more free samples are waiting
Create a free account to unlock the whole GCIA sample bank, or get full access to all 140 practice questions in the simulator.