Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 57 pages
Exam (elaborations)

GIAC NETWORK FORENSIC ANALYST (GNFA) PRACTICE EXAM | QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE

Document preview thumbnail
Preview 4 out of 57 pages

GIAC NETWORK FORENSIC ANALYST (GNFA) PRACTICE EXAM | QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE

Content preview

GIAC NETWORK FORENSIC ANALYST (GNFA) PRACTICE EXAM |
QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM
UPDATE


Core Domains:

1. Network Architecture and Data Acquisition
2. Common Network Protocols (HTTP, DNS, SMB, SMTP, etc.)
3. NetFlow Analysis and Attack Visualization
4. Encryption, Encoding, and TLS Analysis
5. Network Protocol Reverse Engineering
6. Security Event and Incident Logging
7. Network Analysis Tools and Usage (Wireshark, tcpdump, Zeek, etc.)
8. Wireless Network Forensics
9. Open Source Network Security Proxies
10. Threat Hunting and Attack Reconstruction




Introduction

,This comprehensive practice examination is designed to prepare candidates for the GIAC Network Forensic
Analyst (GNFA) certification exam. The assessment evaluates advanced knowledge of network forensic
investigation techniques, including packet analysis, protocol analysis, log aggregation, NetFlow analysis,
encryption decoding, and wireless forensics . Through multiple-choice questions with detailed rationales,
candidates will demonstrate understanding of data acquisition methods, normal and abnormal network
behavior, network evidence collection and analysis, and the reconstruction of network-based attacks. The
examination emphasizes real-world application, investigative methodology, and the practical skills required for
incident response, threat hunting, and network forensic investigations .




QUESTIONS 1–100



Question 1

In the forensic lifecycle, which artifact is considered most volatile and should be captured first?

A. Router configuration files
B. Live RAM captures from a network sensor
C. Archived syslog files
D. NetFlow records stored on a collector

🟢B
🔴 Explanation: RAM holds the most transient data such as active sessions and in-memory packets; it is lost
on power-off, making it the highest-volatility artifact . Volatility is a key principle in digital forensics—the

,most volatile evidence must be captured before it is lost.




Question 2

When placing a network tap for forensic capture, which placement provides the most complete visibility
without introducing latency?

A. Inline between the firewall and ISP router
B. On a switch's mirror (SPAN) port
C. At the aggregation point of core routers
D. Directly on the end-user workstation NIC

🟢C
🔴 Explanation: Tapping at the aggregation point captures traffic from multiple downstream links while
remaining passive, ensuring full visibility and minimal impact . Aggregation points allow collection of traffic
from multiple network segments in a single location.




Question 3

Which of the following network devices is most likely to contain packet-level evidence of lateral movement
across a Windows domain?

A. Load balancer logs
B. DNS recursive resolver cache

, C. SMB traffic captured on a switch
D. DHCP lease tables

🟢C
🔴 Explanation: SMB (Server Message Block) is used for file sharing and remote administration in Windows
environments. Capturing SMB packets reveals file transfers and authentication attempts indicative of lateral
movement . Attackers commonly use SMB for moving laterally across a compromised network .




Question 4

A segmented network isolates the finance department from the rest of the enterprise. Which forensic
challenge does this segmentation create?

A. Increased packet loss on the capture interface
B. Reduced ability to correlate logs across zones
C. Higher probability of MAC address spoofing
D. Inability to capture DNS queries from the finance VLAN

🟢B
🔴 Explanation: Segmentation limits visibility; correlating events across isolated zones requires separate
evidence collection and careful time synchronization . This makes it harder to build a complete attack
timeline spanning multiple network segments.

Document information

Uploaded on
July 17, 2026
Number of pages
57
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PrepPulse1
4.3
(29)
Sold
283
Followers
6
Items
3901
Last sold
13 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions