GCIA Sample Questions

GCIA Sample Questions & Answers

Wireshark fundamentals, tcpdump and BPF filters, and flow-analysis tools carry the most weight, alongside TCP/IP and IDS basics, dissecting IP headers and application protocols, Snort and Zeek rule tuning, and network forensics.

Launch the full GCIA simulator →

Showing 4 of 9 free samples.

  1. Question 1Intermediate

    IPv6 · IPv6 Extension Headers

    An analyst is examining an IPv6 packet capture and finds a packet with a chain of extension headers. The goal is to determine if this packet is being used to bypass a security device that only inspects a limited number of headers. Which extension header, if placed before the Destination Options header, would be the most likely to contain the actual final destination address that a compromised host would process?

    graph TD IPv6_Base["IPv6 Base Header Next Header: Hop-by-Hop"] --> HopByHop["Hop-by-Hop Options Next Header: Routing"] HopByHop --> Routing["Routing Header Next Header: Fragment"] Routing --> Fragment["Fragment Header Next Header: Destination Options"] Fragment --> DestOpts["Destination Options Next Header: TCP"] DestOpts --> TCP_Header["TCP Header & Payload"]
    Show answer & explanation

    Correct answer: C

    The Routing Header (specifically Type 0, RH0, though now deprecated) is designed to specify a list of intermediate nodes for a packet to traverse. The destination address in the main IPv6 header is just the next hop, while the final destination is listed inside the Routing Header itself. Attackers have used this to bypass firewalls that only check the destination address in the main header, as the packet is ultimately delivered to a different address specified in the Routing Header. The other headers serve different purposes: Hop-by-Hop is for all nodes on the path, Fragment deals with packet size, and Destination Options is for the final destination.

  2. Question 2Beginner

    IDS Fundamentals and Network Architecture · IDS Detection Methodologies

    True or False: An anomaly-based Intrusion Detection System (IDS) can potentially detect novel, never-before-seen attacks, but it is also more prone to false positives than a signature-based IDS.

    Show answer & explanation

    Correct answer: A

    This statement is true. Anomaly-based (or behavioral) IDS works by building a baseline of normal network activity and alerting on deviations. This allows it to detect zero-day or novel attacks that don't have a known signature. However, any legitimate but unusual activity can also trigger an alert, leading to a higher rate of false positives compared to signature-based systems, which only alert on specific, pre-defined patterns of malicious activity.

  3. Question 3Intermediate

    Intrusion Detection System Rules · Snort Rule Keywords

    An analyst is writing a Snort rule to detect a specific command-and-control (C2) protocol that establishes a TCP session and then waits for a command from the server. The detection should only trigger on data sent from the C2 server to the infected client after the session is established. Complete the following Snort rule by selecting the correct flow keyword.

    alert tcp $EXTERNAL_NET any -> $HOME_NET 1024: (msg:"ET C2 Trojan Activity"; content:"|01 03 00 00|"; offset:4; depth:4; ____; sid:2034567; rev:1;)

    Show answer & explanation

    Correct answer: A

    The keyword flow:to_client,established is the correct choice. established ensures the rule only applies to packets within a fully established TCP session (after the three-way handshake). to_client tells Snort to only inspect traffic flowing in the direction of the rule's destination ($HOME_NET), which is the infected client. This combination correctly targets C2 commands sent from the server to the client within an active session.

  4. Question 4Beginner

    Application Protocols · FTP Protocol Analysis

    During analysis of a packet capture of an FTP session, an intrusion analyst observes the client sending a PORT 192,168,1,10,10,25 command to the FTP server. What can be definitively concluded from this command?

    Show answer & explanation

    Correct answer: B

    The PORT command is used by an FTP client in active mode to specify the IP address and port on which it will listen for the incoming data connection from the server. The argument 192,168,1,10,10,25 translates to IP 192.168.1.10 and port (10 * 256) + 25 = 2585. Therefore, the server is being instructed to connect back to the client at that address and port to establish the data channel. This is the defining characteristic of active mode FTP.

Ready for the real thing?

The full GCIA simulator has every exam-style question, timed mode, and instant scoring.

Go to the GCIA simulator →