Giac Network Forensic Analyst
Examination Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
1. What is the primary purpose of network forensics?
A. Encrypt network traffic
B. Detect hardware failures
C. Capture and analyze network traffic for security investigations
D. Increase network speed
Answer: C
Rationale: Network forensics focuses on capturing, recording, and
analyzing network traffic to investigate security incidents, intrusions, and
malicious activity.
2. Which protocol operates at the transport layer?
A. HTTP
B. TCP
C. IP
D. ARP
Answer: B
Rationale: TCP operates at the transport layer and provides reliable,
connection-oriented communication between hosts.
,3. Which tool is commonly used for packet capture?
A. Wireshark
B. Photoshop
C. Excel
D. Metasploit only
Answer: A
Rationale: Wireshark is widely used for capturing and analyzing network
packets in forensic investigations.
4. What does a firewall primarily do?
A. Stores logs permanently
B. Filters network traffic based on rules
C. Encrypts files
D. Monitors CPU usage
Answer: B
Rationale: Firewalls enforce security policies by filtering incoming and
outgoing network traffic based on predefined rules.
5. What is a packet in networking?
A. A software application
B. A unit of data transmitted over a network
C. A firewall rule
D. A virus type
Answer: B
Rationale: A packet is a formatted unit of data carried by packet-switched
networks.
6. Which layer does IP operate on?
A. Physical
B. Data Link
, C. Network
D. Application
Answer: C
Rationale: IP operates at the network layer and is responsible for logical
addressing and routing.
7. What is port 80 commonly used for?
A. FTP
B. HTTP
C. SSH
D. DNS
Answer: B
Rationale: Port 80 is the default port for HTTP web traffic.
8. Which protocol is connectionless?
A. TCP
B. UDP
C. FTP
D. SSH
Answer: B
Rationale: UDP is connectionless and does not guarantee delivery or
ordering of packets.
9. What is the purpose of DNS?
A. Encrypt traffic
B. Translate domain names to IP addresses
C. Block malware
D. Route packets
Answer: B
Rationale: DNS resolves human-readable domain names into IP addresses.
Examination Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
1. What is the primary purpose of network forensics?
A. Encrypt network traffic
B. Detect hardware failures
C. Capture and analyze network traffic for security investigations
D. Increase network speed
Answer: C
Rationale: Network forensics focuses on capturing, recording, and
analyzing network traffic to investigate security incidents, intrusions, and
malicious activity.
2. Which protocol operates at the transport layer?
A. HTTP
B. TCP
C. IP
D. ARP
Answer: B
Rationale: TCP operates at the transport layer and provides reliable,
connection-oriented communication between hosts.
,3. Which tool is commonly used for packet capture?
A. Wireshark
B. Photoshop
C. Excel
D. Metasploit only
Answer: A
Rationale: Wireshark is widely used for capturing and analyzing network
packets in forensic investigations.
4. What does a firewall primarily do?
A. Stores logs permanently
B. Filters network traffic based on rules
C. Encrypts files
D. Monitors CPU usage
Answer: B
Rationale: Firewalls enforce security policies by filtering incoming and
outgoing network traffic based on predefined rules.
5. What is a packet in networking?
A. A software application
B. A unit of data transmitted over a network
C. A firewall rule
D. A virus type
Answer: B
Rationale: A packet is a formatted unit of data carried by packet-switched
networks.
6. Which layer does IP operate on?
A. Physical
B. Data Link
, C. Network
D. Application
Answer: C
Rationale: IP operates at the network layer and is responsible for logical
addressing and routing.
7. What is port 80 commonly used for?
A. FTP
B. HTTP
C. SSH
D. DNS
Answer: B
Rationale: Port 80 is the default port for HTTP web traffic.
8. Which protocol is connectionless?
A. TCP
B. UDP
C. FTP
D. SSH
Answer: B
Rationale: UDP is connectionless and does not guarantee delivery or
ordering of packets.
9. What is the purpose of DNS?
A. Encrypt traffic
B. Translate domain names to IP addresses
C. Block malware
D. Route packets
Answer: B
Rationale: DNS resolves human-readable domain names into IP addresses.