GIAC Certified Intrusion Analyst Free Sample Questions

Create a free account to browse all 9 sample questions. The full practice test includes 140 questions. Use the simulator for timed and flashcard mode.

Try Simulator

GCIA Sample Questions

  1. Question 1

    Q1Multiple answers

    An analyst is reviewing logs from a compromised web server to trace lateral movement. They have access to Zeek's conn.log and dce_rpc.log. During the incident window, they observe a successful web shell upload followed by an outbound connection from the web server (192.168.10.5) to a domain controller (192.168.10.10) on TCP port 445. Shortly after, the domain controller makes SMB connections to several other critical servers. Which of the following Zeek log entries would provide the strongest evidence of the specific lateral movement technique used? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    The atsvc endpoint corresponds to the Task Scheduler service. Attackers commonly use this service remotely (e.g., with at or schtasks) to schedule malicious code execution on a target machine, which is a classic lateral movement technique.

    The svcctl endpoint is the Service Control Manager. The CreateServiceW operation indicates that the source host is attempting to create a new service on the destination. This is a very common and powerful lateral movement technique used by tools like PsExec to run code on remote systems.

  2. Question 2

    Q2

    A financial services company has deployed a new NIDS solution at its internet edge. The network architecture uses asymmetric routing for outbound traffic, meaning that traffic leaving the organization may exit through one of two different ISP links, but all return traffic for a given session is guaranteed to arrive via the same link it departed from. The NIDS is placed inline on the primary ISP link but only has a TAP on the secondary link. Analysts are reporting a high volume of alerts for TCP sessions that appear to be incomplete or have anomalous state transitions, but upon investigation, the traffic is benign.

    The security team is also concerned about the NIDS's ability to reassemble fragmented packets and maintain state for application-layer protocols like HTTP/2, which rely on a single, long-lived TCP connection. The primary goal is to achieve reliable threat detection without impacting the performance of the high-speed links. Which of the following is the most effective strategy to address the false positives and ensure reliable detection?

    Show answer & explanation

    Correct answer: B

    This is the most robust architectural solution. By placing the NIDS sensor at a point where it can see all traffic before it is asymmetrically routed, it gains a complete, bidirectional view of every session. This solves the root cause of the problem: the NIDS seeing only one side of a conversation. It allows for proper TCP state tracking, fragment reassembly, and application-layer analysis, thereby eliminating the false positives caused by the split traffic paths. While other options might mitigate parts of the problem, this one resolves it fundamentally.

    graph TD subgraph "Correct Architecture" Internal[Internal Network] --> AggSwitch[Aggregation Switch] AggSwitch --> NIDS[NIDS Sensor] NIDS --> Router[Edge Router] Router --> ISP1[ISP 1] Router --> ISP2[ISP 2] end

  3. Question 3

    Q3

    An analyst is examining an IPv6 packet capture and finds a packet with a chain of extension headers. The goal is to determine if this packet is being used to bypass a security device that only inspects a limited number of headers. Which extension header, if placed before the Destination Options header, would be the most likely to contain the actual final destination address that a compromised host would process?

    graph TD IPv6_Base["IPv6 Base Header Next Header: Hop-by-Hop"] --> HopByHop["Hop-by-Hop Options Next Header: Routing"] HopByHop --> Routing["Routing Header Next Header: Fragment"] Routing --> Fragment["Fragment Header Next Header: Destination Options"] Fragment --> DestOpts["Destination Options Next Header: TCP"] DestOpts --> TCP_Header["TCP Header & Payload"]
    Show answer & explanation

    Correct answer: C

    The Routing Header (specifically Type 0, RH0, though now deprecated) is designed to specify a list of intermediate nodes for a packet to traverse. The destination address in the main IPv6 header is just the next hop, while the final destination is listed inside the Routing Header itself. Attackers have used this to bypass firewalls that only check the destination address in the main header, as the packet is ultimately delivered to a different address specified in the Routing Header. The other headers serve different purposes: Hop-by-Hop is for all nodes on the path, Fragment deals with packet size, and Destination Options is for the final destination.

  4. Question 4

    Q4

    True or False: An anomaly-based Intrusion Detection System (IDS) can potentially detect novel, never-before-seen attacks, but it is also more prone to false positives than a signature-based IDS.

    Show answer & explanation

    Correct answer: A

    This statement is true. Anomaly-based (or behavioral) IDS works by building a baseline of normal network activity and alerting on deviations. This allows it to detect zero-day or novel attacks that don't have a known signature. However, any legitimate but unusual activity can also trigger an alert, leading to a higher rate of false positives compared to signature-based systems, which only alert on specific, pre-defined patterns of malicious activity.

Register free to unlock 5 more sample questions

Create a free account to continue with the rest of the GCIA sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 140 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon