• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 66 pages
Exam (elaborations)

Giac Network Forensic Analyst (Gnfa) Exam With Questions And Verified Answers, Plus Detailed Rationales/Expert Verified For Guaranteed Pass 2026/Latest Update/Instant Download Pdf

Document preview thumbnail
Preview 4 out of 66 pages

GIAC NETWORK FORENSIC ANALYST (GNFA) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF GIAC NETWORK FORENSIC ANALYST (GNFA) EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

GIAC NETWORK FORENSIC ANALYST
(GNFA) EXAM WITH QUESTIONS AND
VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A network forensic analyst is investigating a suspected data-exfiltration
incident. A packet capture contains a large amount of TCP traffic
between an internal workstation and an external IP address. The analyst
observes that the TCP three-way handshake completed successfully,
followed by sustained bidirectional traffic. However, the application
protocol is not immediately identifiable because the payload appears
encrypted. Which observation would provide the strongest initial
evidence that the TCP session itself is valid and not merely spoofed
traffic?
A. The source port is 443
B. The destination IP address belongs to a cloud provider
C. The TCP handshake contains SYN, SYN/ACK, and ACK packets
with consistent sequence and acknowledgment numbers
D. The packets have a high TTL value
E. The application payload contains printable ASCII characters
Answer: C. The TCP handshake contains SYN, SYN/ACK, and
ACK packets with consistent sequence and acknowledgment
numbers
Rationale: A valid TCP three-way handshake, with coherent sequence
and acknowledgment progression, provides strong evidence that the
session was established through normal TCP state transitions. The
port number alone does not prove the application or legitimacy of the
1

,communication, and cloud-provider ownership is not evidence of
maliciousness. TTL and payload characteristics can provide
supporting clues but do not establish TCP-session validity.


2.
An analyst receives a PCAP file containing a suspected intrusion. The
capture begins several minutes after the suspected initial compromise.
The analyst identifies multiple established TCP connections but cannot
determine how the sessions originated. Which limitation is most
important when interpreting the evidence?
A. TCP cannot be analyzed without UDP traffic
B. The absence of the beginning of a session can prevent reconstruction
of the initial connection establishment and preceding events
C. PCAP files cannot contain timestamps
D. Established TCP connections are automatically invalid if the
handshake is missing
E. Network forensic analysis requires DNS logs exclusively
Answer: B. The absence of the beginning of a session can prevent
reconstruction of the initial connection establishment and preceding
events
Rationale: Network forensic conclusions depend heavily on capture
scope. If the PCAP begins after connection establishment, the analyst
may be unable to determine the original SYN exchange, initial
sequence numbers, preceding DNS activity, or earlier
communications. The session can still be analyzed, but conclusions
about how it began must be appropriately qualified.


3.
A workstation generates the following DNS request:
2

,update-service.example.net
Immediately afterward, it establishes a TCP connection to the returned
IP address. Five minutes later, the same host makes dozens of DNS
queries for randomly generated-looking subdomains under the same
parent domain. What investigative hypothesis should receive the highest
priority?
A. Normal browser caching
B. Possible DNS-based command-and-control or domain-generation
activity
C. ARP cache poisoning
D. DHCP exhaustion
E. ICMP fragmentation
Answer: B. Possible DNS-based command-and-control or domain-
generation activity
Rationale: Repeated queries containing apparently random or
algorithmically generated labels can indicate domain-generation
algorithms, DNS-based C2, tunneling, or malware beaconing. The
analyst should correlate query frequency, NXDOMAIN responses,
entropy, timing, returned IP addresses, and subsequent connections
before determining the precise technique.


4.
During TCP stream reconstruction, an analyst observes that one packet
contains a sequence number that falls outside the expected receive
window and is subsequently retransmitted with the correct sequence
number. What should the analyst conclude?
A. The host necessarily experienced a compromise
B. The original packet must contain malware
C. The event may represent normal TCP retransmission or out-of-

3

, window handling and requires contextual interpretation
D. The packet capture is automatically invalid
E. The connection must have been UDP
Answer: C. The event may represent normal TCP retransmission or
out-of-window handling and requires contextual interpretation
Rationale: TCP sequence-number anomalies can result from packet
loss, retransmission, capture artifacts, reordering, asymmetric capture,
or deliberate manipulation. A single anomalous packet is insufficient
evidence of compromise. Analysts should examine surrounding
packets, acknowledgment behavior, retransmissions, timestamps, and
capture topology.


5.
A network forensic investigator is examining a suspected HTTP-based
malware infection. The PCAP shows:
GET /images/logo.png HTTP/1.1
but the response contains an executable PE file rather than an image.
Which technique would be most useful for identifying the transferred
object?
A. Examine only the destination TCP port
B. Perform file carving or HTTP object extraction from the
reconstructed stream
C. Delete all HTTP headers
D. Analyze ARP packets only
E. Examine ICMP echo requests
Answer: B. Perform file carving or HTTP object extraction from the
reconstructed stream



4

Document information

Uploaded on
August 28, 2026
Number of pages
66
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$24.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
bookseller
5.0
(1)
Sold
8
Followers
0
Items
1261
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions