Skip to content

GCIA Practice Questions

Prepare for GCIA with more than an answer.

140 questions in the full set9 sample questionsUpdated Sep 29, 2026
Exam fee
$2499 USD
Level
Practitioner
Valid for
4 years
Domains covered on the exam 5
  1. TCP/IP Fundamentals and Network Architecture15%
  2. Packet Analysis and Protocol Dissection20%
  3. Traffic Analysis Tools and Techniques25%
  4. Intrusion Detection Systems20%
  5. Network Forensics and Threat Hunting20%
  1. 1

    A SOC analyst is investigating an alert for potential lateral movement originating from a compromised web server (10.10.50.100) towards a domain controller (10.10.10.5). The analyst has access to Zeek logs generated from traffic between the two systems. The goal is to find evidence of an attacker using PsExec or a similar tool for remote command execution. Which TWO of the following log entries would be the strongest indicators of this activity? (Select TWO)

    Show answer details

    Correct answer: A, B

    PsExec works by first copying an executable to the ADMIN$ share of the target machine, which would be logged in smb_files.log. It then uses the Service Control Manager RPC interface (svcctl) to create a new service (CreateServiceW operation) that runs the uploaded executable. Therefore, seeing both of these events in Zeek logs is a very strong indicator of PsExec-style lateral movement. An RDP connection is another form of lateral movement but is distinct from PsExec's mechanism. An epmapper operation is a generic DCE/RPC lookup and not specific enough. A conn.log entry for port 445 is expected in an environment using SMB and is not, by itself, a strong indicator of malicious activity.

  2. 2

    An intrusion analyst is tasked with writing a Suricata rule to detect potential command-and-control (C2) traffic that uses DNS tunneling. The detection strategy is to flag any DNS query for a TXT record that contains a high-entropy payload, which is characteristic of encoded C2 data. The target domain for this C2 is *.c2-evil.net. Which rule is crafted most effectively for this purpose?

    Show answer details

    Correct answer: C

    This rule is the most effective and precise. It uses Suricata's application-layer parsing (app-layer-event:dns.query) to specifically target DNS queries. It correctly filters for the query type (dns.query.type:"TXT"), uses the built-in entropy calculation on the queried name (dns.query.name.entropy:>4.5) to identify randomness, and correctly checks if the query ends with the suspected C2 domain (dns.query.name.endswith:".c2-evil.net"). The other options are either too generic, use incorrect syntax, or lack the critical entropy detection component.

  3. 3

    During a forensic investigation of a large PCAP file (>50GB), an analyst needs to quickly extract all files transferred over unencrypted HTTP and save them to a directory for malware analysis. The analyst wants to use a command-line tool for efficiency and to script the process for future use. Which tshark command will accomplish this task most effectively?

    Show answer details

    Correct answer: B

    The --export-objects flag in tshark is the designated feature for reassembling and exporting objects (files) from various protocols. The syntax http,./extracted_files tells tshark to extract all objects it can find from the HTTP protocol and save them into the extracted_files directory. This is the most direct, efficient, and reliable command-line method for this task. The other options either extract the wrong data, are syntactically incorrect, or would require significant manual processing to reconstruct the files.

  4. 4

    An analyst is reviewing logs from a compromised web server to trace lateral movement. They have access to Zeek's conn.log and dce_rpc.log. During the incident window, they observe a successful web shell upload followed by an outbound connection from the web server (192.168.10.5) to a domain controller (192.168.10.10) on TCP port 445. Shortly after, the domain controller makes SMB connections to several other critical servers. Which of the following Zeek log entries would provide the strongest evidence of the specific lateral movement technique used? (Select TWO)

    Show answer details

    Correct answer: B, D

    The atsvc endpoint corresponds to the Task Scheduler service. Attackers commonly use this service remotely (e.g., with at or schtasks) to schedule malicious code execution on a target machine, which is a classic lateral movement technique.

    The svcctl endpoint is the Service Control Manager. The CreateServiceW operation indicates that the source host is attempting to create a new service on the destination. This is a very common and powerful lateral movement technique used by tools like PsExec to run code on remote systems.

Create an account to continue.