(GNFA) EXAM WITH QUESTIONS AND
VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A network forensic analyst is investigating a suspected data-exfiltration
incident. A packet capture contains a large amount of TCP traffic
between an internal workstation and an external IP address. The analyst
observes that the TCP three-way handshake completed successfully,
followed by sustained bidirectional traffic. However, the application
protocol is not immediately identifiable because the payload appears
encrypted. Which observation would provide the strongest initial
evidence that the TCP session itself is valid and not merely spoofed
traffic?
A. The source port is 443
B. The destination IP address belongs to a cloud provider
C. The TCP handshake contains SYN, SYN/ACK, and ACK packets
with consistent sequence and acknowledgment numbers
D. The packets have a high TTL value
E. The application payload contains printable ASCII characters
Answer: C. The TCP handshake contains SYN, SYN/ACK, and
ACK packets with consistent sequence and acknowledgment
numbers
Rationale: A valid TCP three-way handshake, with coherent sequence
and acknowledgment progression, provides strong evidence that the
session was established through normal TCP state transitions. The
port number alone does not prove the application or legitimacy of the
1
,communication, and cloud-provider ownership is not evidence of
maliciousness. TTL and payload characteristics can provide
supporting clues but do not establish TCP-session validity.
2.
An analyst receives a PCAP file containing a suspected intrusion. The
capture begins several minutes after the suspected initial compromise.
The analyst identifies multiple established TCP connections but cannot
determine how the sessions originated. Which limitation is most
important when interpreting the evidence?
A. TCP cannot be analyzed without UDP traffic
B. The absence of the beginning of a session can prevent reconstruction
of the initial connection establishment and preceding events
C. PCAP files cannot contain timestamps
D. Established TCP connections are automatically invalid if the
handshake is missing
E. Network forensic analysis requires DNS logs exclusively
Answer: B. The absence of the beginning of a session can prevent
reconstruction of the initial connection establishment and preceding
events
Rationale: Network forensic conclusions depend heavily on capture
scope. If the PCAP begins after connection establishment, the analyst
may be unable to determine the original SYN exchange, initial
sequence numbers, preceding DNS activity, or earlier
communications. The session can still be analyzed, but conclusions
about how it began must be appropriately qualified.
3.
A workstation generates the following DNS request:
2
,update-service.example.net
Immediately afterward, it establishes a TCP connection to the returned
IP address. Five minutes later, the same host makes dozens of DNS
queries for randomly generated-looking subdomains under the same
parent domain. What investigative hypothesis should receive the highest
priority?
A. Normal browser caching
B. Possible DNS-based command-and-control or domain-generation
activity
C. ARP cache poisoning
D. DHCP exhaustion
E. ICMP fragmentation
Answer: B. Possible DNS-based command-and-control or domain-
generation activity
Rationale: Repeated queries containing apparently random or
algorithmically generated labels can indicate domain-generation
algorithms, DNS-based C2, tunneling, or malware beaconing. The
analyst should correlate query frequency, NXDOMAIN responses,
entropy, timing, returned IP addresses, and subsequent connections
before determining the precise technique.
4.
During TCP stream reconstruction, an analyst observes that one packet
contains a sequence number that falls outside the expected receive
window and is subsequently retransmitted with the correct sequence
number. What should the analyst conclude?
A. The host necessarily experienced a compromise
B. The original packet must contain malware
C. The event may represent normal TCP retransmission or out-of-
3
, window handling and requires contextual interpretation
D. The packet capture is automatically invalid
E. The connection must have been UDP
Answer: C. The event may represent normal TCP retransmission or
out-of-window handling and requires contextual interpretation
Rationale: TCP sequence-number anomalies can result from packet
loss, retransmission, capture artifacts, reordering, asymmetric capture,
or deliberate manipulation. A single anomalous packet is insufficient
evidence of compromise. Analysts should examine surrounding
packets, acknowledgment behavior, retransmissions, timestamps, and
capture topology.
5.
A network forensic investigator is examining a suspected HTTP-based
malware infection. The PCAP shows:
GET /images/logo.png HTTP/1.1
but the response contains an executable PE file rather than an image.
Which technique would be most useful for identifying the transferred
object?
A. Examine only the destination TCP port
B. Perform file carving or HTTP object extraction from the
reconstructed stream
C. Delete all HTTP headers
D. Analyze ARP packets only
E. Examine ICMP echo requests
Answer: B. Perform file carving or HTTP object extraction from the
reconstructed stream
4