Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by GIAC
Exam Format
Registration
Validity
GNFA Exam Topics and Domains
GNFA is organized into 8 weighted domains. Expect to work with SIEM platforms, FTPS, Network monitoring tools, Wireless access points, and more.
Common Network Protocols
Core Protocol Analysis
- Demonstrate understanding of the behavior, security risks and controls of common network protocols
- Analyze protocol-specific artifacts to identify security incidents
- Reconstruct network sessions from packet captures
Encryption and Encoding
SSL/TLS Analysis
- Understand techniques and practices used to encode and encrypt common network traffic
- Identify common attacks on encryption controls
- Analyze encrypted traffic metadata for threat detection
Encoding Schemes
- Recognize and decode common encoding schemes in network traffic
- Identify obfuscation techniques used by attackers
NetFlow Analysis and Attack Visualization
NetFlow Fundamentals
- Demonstrate familiarity with NetFlow data and information sources
- Use NetFlow data to identify network attacks
- Visualize network traffic patterns for threat detection
Attack Visualization
- Create effective visualizations of network attacks
- Use visual analysis to identify attacker tactics and techniques
- Communicate findings through visual representations
Network Architecture
Network Design and Deployment
- Understand the process to design and deploy a network employing diverse transmission and collection technologies
- Identify optimal locations for forensic evidence collection
- Recognize network design elements that impact forensic investigations
Network Protocol Reverse Engineering
Protocol Analysis and Reverse Engineering
- Demonstrate knowledge of tools and techniques required to analyze diverse protocols and data traversing a network environment
- Reverse engineer unknown or proprietary protocols
- Create custom tools for protocol analysis
Open Source Network Security Proxies
Proxy Architecture and Analysis
- Understand architecture, deployment, benefits and weaknesses of network security proxies
- Analyze common log formats and data flows from proxy systems
- Extract forensic artifacts from proxy logs and systems
Security Event and Incident Logging
Log Aggregation and Analysis
- Demonstrate familiarity with diverse log formats, protocols and the security impact of event generating processes
- Deploy and configure logging aggregators effectively
- Correlate logs from multiple sources to reconstruct incidents
Wireless Network Analysis
Wireless Forensics
- Identify and control the risks associated with wireless technologies, protocols and infrastructure
- Capture and analyze wireless network traffic
- Detect and investigate wireless security incidents
How do I earn this certification?
Passing GNFA earns the GIAC Network Forensic Analyst certification. It sits in the Digital Forensics and Incident Response track.
- GDAT - GIAC Defending Advanced ThreatsAdvanced threat detection and response capabilities
- GRID - GIAC Response and Industrial Defense ICS/SCADA incident response specialization
- GCTI - GIAC Cyber Threat IntelligenceThreat intelligence analysis and application
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for GNFA is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2026
- Zeek (Bro) Network Security Monitor 6.x Core tool for network forensics and log analysis • Release date: 2025
- Arkime (formerly Moloch) 5.x Large-scale packet capture and analysis platform • Release date: 2025
- Wireshark 4.x Primary packet analysis tool with continuous protocol updates • Release date: 2024-2025
- SOF-ELK Latest SANS-maintained ELK distribution for security forensics • Release date: Ongoing updates
Who should take this exam?
This exam is typically taken by Incident response team members and Forensic analysts.
- Understanding of TCP/IP networking
- Experience with packet analysis tools
- Familiarity with network protocols
- Basic knowledge of network security concepts
- Recommended training: SANS FOR572