GIAC Network Forensic Analyst (GNFA) - GNFA Exam Practice Test
Question 1
A security analyst is reviewing NetFlow data and notices a sudden increase in outbound connections to an unfamiliar IP address. The majority of the connections originate from a single internal workstation. What is the most likely cause?
Response:
Response:
Correct Answer: A
Question 2
Which open-source tools are commonly used for network security proxying?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: B,C
Question 3
Which of the following NetFlow-based anomalies could indicate a Distributed Denial-of-Service (DDoS) attack?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: C,D
Question 4
Which of the following are security risks associated with FTP?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: A,B
Question 5
Which of the following hashing algorithms is considered weak due to its vulnerability to collisions?
Response:
Response:
Correct Answer: B
Question 6
Which network security proxy tool is commonly used to analyze and modify HTTPS traffic?
Response:
Response:
Correct Answer: C
Question 7
Which of the following network components is responsible for enforcing security policies between different network segments?
Response:
Response:
Correct Answer: B
Question 8
Which of the following are features of a forward proxy?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: A,D
Question 9
Which of the following best describes an SIEM (Security Information and Event Management) system?
Response:
Response:
Correct Answer: D
Question 10
Which challenges are commonly encountered when reverse engineering network protocols?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: A,C

