GIAC Network Forensic Analyst (GNFA) - GNFA Exam Practice Test
You are analyzing network traffic and find a series of communications using an unknown protocol. The traffic appears structured, but there is no official documentation available. What should be your first step?
Response:
Response:
Correct Answer: B
Vote an answer
Which of the following are key benefits of centralizing security event logs?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: B,C
Vote an answer
Which of the following hashing algorithms is considered weak due to its vulnerability to collisions?
Response:
Response:
Correct Answer: D
Vote an answer
What methods are used to identify the structure of an unknown network protocol?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: A,B
Vote an answer
What are common characteristics of rogue access points?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: B,C
Vote an answer
Which of the following best describes an SIEM (Security Information and Event Management) system?
Response:
Response:
Correct Answer: A
Vote an answer
Which of the following encryption algorithms are considered secure for modern cryptographic use?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: A,C
Vote an answer
Which of the following is a security risk associated with open Wi-Fi networks?
Response:
Response:
Correct Answer: C
Vote an answer
What is the primary purpose of NetFlow in network security analysis?
Response:
Response:
Correct Answer: D
Vote an answer
What methods are used to identify the structure of an unknown network protocol?
(Select two.)
Response:
(Select two.)
Response:
Correct Answer: A,B
Vote an answer