GIAC Network Forensic Analyst (GNFA) Sample Questions:
1. Which of the following can be used to detect rogue access points in a wireless network?
Response:
A) NetFlow
B) Syslog
C) Wireless Intrusion Detection System (WIDS)
D) Wireshark
2. A security analyst is reviewing NetFlow data and notices a sudden increase in outbound connections to an unfamiliar IP address. The majority of the connections originate from a single internal workstation. What is the most likely cause?
Response:
A) Normal traffic fluctuation
B) An error in NetFlow collection
C) A botnet infection exfiltrating data
D) A user downloading a large file
3. What is a common attack technique used to intercept wireless network traffic?
Response:
A) ARP Spoofing
B) Man-in-the-Middle (MITM)
C) DNS Tunneling
D) Cross-Site Scripting (XSS)
4. Which protocol is commonly used for network device management and monitoring?
Response:
A) SNMP
B) DHCP
C) HTTP
D) FTP
5. What is a key advantage of using 802.1X authentication for wireless security?
Response:
A) It allows access to anyone with a Wi-Fi password
B) It prevents rogue access points from appearing
C) It enables encrypted authentication for each user
D) It reduces the need for network segmentation
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: C | Question # 3 Answer: B | Question # 4 Answer: A | Question # 5 Answer: C |

We're so confident of our products that we provide no hassle product exchange.


By Ingram


