GIAC NETWORK FORENSIC ANALYST (GNFA) PRACTICE EXAM |
QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM
UPDATE
Core Domains:
1. Network Architecture and Data Acquisition
2. Common Network Protocols (HTTP, DNS, SMB, SMTP, etc.)
3. NetFlow Analysis and Attack Visualization
4. Encryption, Encoding, and TLS Analysis
5. Network Protocol Reverse Engineering
6. Security Event and Incident Logging
7. Network Analysis Tools and Usage (Wireshark, tcpdump, Zeek, etc.)
8. Wireless Network Forensics
9. Open Source Network Security Proxies
10. Threat Hunting and Attack Reconstruction
Introduction
,This comprehensive practice examination is designed to prepare candidates for the GIAC Network Forensic
Analyst (GNFA) certification exam. The assessment evaluates advanced knowledge of network forensic
investigation techniques, including packet analysis, protocol analysis, log aggregation, NetFlow analysis,
encryption decoding, and wireless forensics . Through multiple-choice questions with detailed rationales,
candidates will demonstrate understanding of data acquisition methods, normal and abnormal network
behavior, network evidence collection and analysis, and the reconstruction of network-based attacks. The
examination emphasizes real-world application, investigative methodology, and the practical skills required for
incident response, threat hunting, and network forensic investigations .
QUESTIONS 1–100
Question 1
In the forensic lifecycle, which artifact is considered most volatile and should be captured first?
A. Router configuration files
B. Live RAM captures from a network sensor
C. Archived syslog files
D. NetFlow records stored on a collector
🟢B
🔴 Explanation: RAM holds the most transient data such as active sessions and in-memory packets; it is lost
on power-off, making it the highest-volatility artifact . Volatility is a key principle in digital forensics—the
,most volatile evidence must be captured before it is lost.
Question 2
When placing a network tap for forensic capture, which placement provides the most complete visibility
without introducing latency?
A. Inline between the firewall and ISP router
B. On a switch's mirror (SPAN) port
C. At the aggregation point of core routers
D. Directly on the end-user workstation NIC
🟢C
🔴 Explanation: Tapping at the aggregation point captures traffic from multiple downstream links while
remaining passive, ensuring full visibility and minimal impact . Aggregation points allow collection of traffic
from multiple network segments in a single location.
Question 3
Which of the following network devices is most likely to contain packet-level evidence of lateral movement
across a Windows domain?
A. Load balancer logs
B. DNS recursive resolver cache
, C. SMB traffic captured on a switch
D. DHCP lease tables
🟢C
🔴 Explanation: SMB (Server Message Block) is used for file sharing and remote administration in Windows
environments. Capturing SMB packets reveals file transfers and authentication attempts indicative of lateral
movement . Attackers commonly use SMB for moving laterally across a compromised network .
Question 4
A segmented network isolates the finance department from the rest of the enterprise. Which forensic
challenge does this segmentation create?
A. Increased packet loss on the capture interface
B. Reduced ability to correlate logs across zones
C. Higher probability of MAC address spoofing
D. Inability to capture DNS queries from the finance VLAN
🟢B
🔴 Explanation: Segmentation limits visibility; correlating events across isolated zones requires separate
evidence collection and careful time synchronization . This makes it harder to build a complete attack
timeline spanning multiple network segments.
QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM
UPDATE
Core Domains:
1. Network Architecture and Data Acquisition
2. Common Network Protocols (HTTP, DNS, SMB, SMTP, etc.)
3. NetFlow Analysis and Attack Visualization
4. Encryption, Encoding, and TLS Analysis
5. Network Protocol Reverse Engineering
6. Security Event and Incident Logging
7. Network Analysis Tools and Usage (Wireshark, tcpdump, Zeek, etc.)
8. Wireless Network Forensics
9. Open Source Network Security Proxies
10. Threat Hunting and Attack Reconstruction
Introduction
,This comprehensive practice examination is designed to prepare candidates for the GIAC Network Forensic
Analyst (GNFA) certification exam. The assessment evaluates advanced knowledge of network forensic
investigation techniques, including packet analysis, protocol analysis, log aggregation, NetFlow analysis,
encryption decoding, and wireless forensics . Through multiple-choice questions with detailed rationales,
candidates will demonstrate understanding of data acquisition methods, normal and abnormal network
behavior, network evidence collection and analysis, and the reconstruction of network-based attacks. The
examination emphasizes real-world application, investigative methodology, and the practical skills required for
incident response, threat hunting, and network forensic investigations .
QUESTIONS 1–100
Question 1
In the forensic lifecycle, which artifact is considered most volatile and should be captured first?
A. Router configuration files
B. Live RAM captures from a network sensor
C. Archived syslog files
D. NetFlow records stored on a collector
🟢B
🔴 Explanation: RAM holds the most transient data such as active sessions and in-memory packets; it is lost
on power-off, making it the highest-volatility artifact . Volatility is a key principle in digital forensics—the
,most volatile evidence must be captured before it is lost.
Question 2
When placing a network tap for forensic capture, which placement provides the most complete visibility
without introducing latency?
A. Inline between the firewall and ISP router
B. On a switch's mirror (SPAN) port
C. At the aggregation point of core routers
D. Directly on the end-user workstation NIC
🟢C
🔴 Explanation: Tapping at the aggregation point captures traffic from multiple downstream links while
remaining passive, ensuring full visibility and minimal impact . Aggregation points allow collection of traffic
from multiple network segments in a single location.
Question 3
Which of the following network devices is most likely to contain packet-level evidence of lateral movement
across a Windows domain?
A. Load balancer logs
B. DNS recursive resolver cache
, C. SMB traffic captured on a switch
D. DHCP lease tables
🟢C
🔴 Explanation: SMB (Server Message Block) is used for file sharing and remote administration in Windows
environments. Capturing SMB packets reveals file transfers and authentication attempts indicative of lateral
movement . Attackers commonly use SMB for moving laterally across a compromised network .
Question 4
A segmented network isolates the finance department from the rest of the enterprise. Which forensic
challenge does this segmentation create?
A. Increased packet loss on the capture interface
B. Reduced ability to correlate logs across zones
C. Higher probability of MAC address spoofing
D. Inability to capture DNS queries from the finance VLAN
🟢B
🔴 Explanation: Segmentation limits visibility; correlating events across isolated zones requires separate
evidence collection and careful time synchronization . This makes it harder to build a complete attack
timeline spanning multiple network segments.