GIAC · Certified Intrusion Analyst GCIA

GIAC Certified Intrusion Analyst GCIA Exam Practice Questions

507 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 507 questions in this pack

Question 1

Andrew works as a System Administrator for NetPerfect Inc. All client computers on the network run on Mac OS X. The Sales Manager of the company complains that his MacBook is not able to boot. Andrew wants to check the booting process. He suspects that an error persists in the bootloader of Mac OS X. Which of the following is the default bootloader on Mac OS X that he should use to resolve the issue?

  1. LILO
  2. BootX
  3. NT Loader
  4. GRUB
Show answer and explanation

Correct answer: B. BootX

BootX is the default bootloader for Mac OS X systems. It is responsible for loading the kernel and initializing the boot process on Apple Macintosh computers. LILO and GRUB are Linux bootloaders, while NT Loader is used by Windows systems.

Why the other options are wrong

  • A. LILO is the Linux Loader used on Linux systems, not Mac OS X.
  • C. NT Loader is the bootloader for Windows NT-based systems, not Mac OS X.
  • D. GRUB is the Grand Unified Bootloader used primarily on Linux systems, not Mac OS X.

Question 2

Sasha wants to add an entry to your DNS database for your mail server.

Which of the following types of resource records will she use to accomplish this?

  1. ANAME
  2. SOA
  3. MX
  4. CNAME
Show answer and explanation

Correct answer: C. MX

MX (Mail Exchange) records are used in DNS to specify the mail servers responsible for receiving email for a domain. They are essential for directing email traffic to the correct mail server. ANAME is not a standard DNS record type, SOA defines zone parameters, and CNAME creates aliases for hostnames.

Why the other options are wrong

  • A. ANAME is not a standard DNS resource record type.
  • B. SOA records define Start of Authority parameters for a DNS zone, not mail server entries.
  • D. CNAME records create canonical name aliases but are not used specifically for mail server entries.

Question 3

John, a novice web user, makes a new E-mail account and keeps his password as "apple", his favorite fruit. John's password is vulnerable to which of the following password cracking attacks?

Each correct answer represents a complete solution.

Choose all that apply.

  1. Dictionary attack
  2. Hybrid attack
  3. Brute Force attack
  4. Rule based attack
Show answer and explanation

Correct answer: A, B, C

A. Dictionary attack B. Hybrid attack C. Brute Force attack "apple" is a short, common English word, so it falls to several cracking techniques. A dictionary attack simply tries every word in a wordlist, and "apple" is in every wordlist. A hybrid attack starts from dictionary words and appends or alters characters, so the base word "apple" is recovered along the way. A brute force attack tries every possible character combination, and a five-character lowercase password is exhausted in seconds. All three therefore succeed against this password.

Why the other options are wrong

  • D. A rule-based attack is used when the attacker already knows something about the password composition policy (length, required character classes) and builds rules from that knowledge; nothing here gives the attacker such prior information about the password's structure.

See all 10 free questions Get the full pack, US$39

507 practice questions for GIAC Certified Intrusion Analyst (GCIA), with full explanations.

Every question comes with the correct answer and a clear explanation. Mapped to the current GCIA exam objectives.

  • 507 questions mapped to the GCIA exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

The GCIA costs US$999 per attempt. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 507 questions

What makes the GCIA hard

The GCIA goes deeper on network traffic than most security professionals have ever had to go. It is 106 questions in four hours, open book, with a 67% pass mark.

This is not about recognising attack patterns. It is about understanding protocol behaviour at the packet level: TCP/IP internals, IDS signature development, application-layer protocol analysis, network forensics, and detecting attackers who are actively trying to evade defences. Most candidates who struggle have not gone deep enough on the technical side.

This pack has 507 practice questions for the GCIA, covering that much ground because the exam does, so it is a way to find the gaps before GIAC does.

About the exam

The GCIA validates hands-on skill in monitoring and analysing network traffic to detect and respond to intrusions. It covers the full spectrum from low-level packet analysis to IDS tuning and network forensics, making it one of the most technically demanding network defence certifications available. It is aligned to SANS SEC503.

Exam topics

  • TCP/IP and protocol analysis: deep understanding of network protocols and packet behaviour
  • Traffic analysis: capturing, filtering, and interpreting network traffic
  • Intrusion detection: configuring and tuning IDS/IPS systems
  • Signature development: writing and refining detection signatures
  • Network forensics: reconstructing events from packet captures
  • Application protocol analysis: HTTP, DNS, SMTP, and other application-layer protocols
  • Evasion techniques: detecting attackers attempting to bypass network defences

106 questions, 4 hours, passing score 67%, open book, valid 4 years, maps to DoD 8140.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Certified Intrusion Analyst GCIA pack?

507 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.