GIAC GNFA Exam Overview:
| Certification Vendor: | GIAC (Global Information Assurance Certification) |
|---|---|
| Exam Name: | GIAC Network Forensic Analyst |
| Exam Number: | GNFA |
| Passing Score: | 70% |
| Exam Format: | Multiple choice, Open-book, CyberLive practical performance-based questions, Proctored |
| Certificate Validity Period: | 4 years |
| Related Certifications: | GIAC Certified Forensic Examiner (GCFE) GIAC Certified Forensic Analyst (GCFA) GIAC Reverse Engineering Malware (GREM) |
| Exam Duration: | 180 minutes |
| Exam Price: | $999 USD |
| Real Exam Qty: | 66 |
| Available Languages: | English |
| Recommended Training: | SANS FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response |
| Exam Registration: | GIAC Official Registration Pearson VUE Scheduling |
| Sample Questions: | GIAC GNFA Sample Questions |
| Exam Way: | Web-based, proctored; remote via ProctorU or onsite at Pearson VUE test centers; 120 days access from activation |
| Pre Condition: | No formal prerequisites; recommended background in networking, security, and digital forensics; SANS FOR572 training strongly recommended but not required |
| Official Syllabus URL: | https://www.giac.org/certifications/network-forensic-analyst-gnfa |
GIAC GNFA Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Encryption and Encoding Techniques | - Common encoding methods and data obfuscation - Attacks against encryption and encoding controls - Encryption algorithms, usage, and implementation |
| Security Event and Incident Logging | - Deployment, aggregation, and retention strategies - Correlating logs to reconstruct events and activity - Log formats, standards, and protocol details |
| Open-Source Network Security Proxies | - Benefits, limitations, and security weaknesses - Architecture, deployment, and operational characteristics - Log formats, data flow, and forensic value |
| Network Analysis Tools and Usage | - Command-line and GUI-based forensic utilities - Traffic capture and analysis tools (tcpdump, Wireshark, etc.) - Practical application in investigation and analysis |
| NetFlow Analysis and Attack Visualization | - Using flow data to identify anomalies, attacks, and lateral movement - Visualization and analysis tools and techniques - NetFlow, IPFIX, and flow data formats |
| Network Protocol Reverse Engineering | - Identifying malicious or non-standard communications - Extracting structure, behavior, and data from traffic - Tools and methodologies for analyzing unknown or proprietary protocols |
| Network Architecture and Design | - Design considerations for forensics and evidence collection - Segmentation, filtering, and security architecture principles - Network topologies, transmission technologies, and collection points |
| Wireless Network Analysis | - Wireless protocols, operation, and security risks - Threats, attacks, and forensic investigation methods - Capture, analysis, and interpretation of wireless traffic |
| Common Network Protocols | - Protocol behavior, characteristics, and normal operation - Security risks, vulnerabilities, and mitigation controls - TCP, UDP, IP, HTTP, DNS, SMTP, FTP, and other core protocols |
GIAC Network Forensic Analyst (GNFA) Sample Questions:
Question 1
Which of the following is a benefit of using a transparent proxy?
Response:
A. It eliminates the need for network monitoring
B. It blocks all traffic from unknown sources
C. It does not require client-side configuration
D. It encrypts all internet traffic by default
Question 2
What are common characteristics of rogue access points?
(Select two.)
Response:
A. They broadcast unauthorized SSIDs
B. They only exist in wired networks
C. They can be used for phishing attacks
D. They always use enterprise-level encryption
Question 3
What is the primary purpose of a network security proxy?
Response:
A. To replace the need for firewalls
B. To encrypt all internal network traffic
C. To block all outbound connections from an organization
D. To act as an intermediary between clients and servers, filtering and monitoring traffic
Question 4
What methods are used to identify the structure of an unknown network protocol?
(Select two.)
Response:
A. Packet inspection
B. Watching video tutorials
C. Reverse engineering binaries
D. Static code analysis
Question 5
What is a common attack technique used to intercept wireless network traffic?
Response:
A. DNS Tunneling
B. Cross-Site Scripting (XSS)
C. ARP Spoofing
D. Man-in-the-Middle (MITM)
Solutions:
| Question 1 Answer: C | Question 2 Answer: A,C | Question 3 Answer: D | Question 4 Answer: A,C | Question 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Neil

