GCIA Practice Questions
Prepare for GCIA with more than an answer.
- Exam fee
- $2499 USD
- Level
- Practitioner
- Valid for
- 4 years
Domains covered on the exam 5
- TCP/IP Fundamentals and Network Architecture15%
- Packet Analysis and Protocol Dissection20%
- Traffic Analysis Tools and Techniques25%
- Intrusion Detection Systems20%
- Network Forensics and Threat Hunting20%
- 1
A SOC analyst is investigating an alert for potential lateral movement originating from a compromised web server (10.10.50.100) towards a domain controller (10.10.10.5). The analyst has access to Zeek logs generated from traffic between the two systems. The goal is to find evidence of an attacker using PsExec or a similar tool for remote command execution. Which TWO of the following log entries would be the strongest indicators of this activity? (Select TWO)
Show answer details
Correct answer: A, B
PsExec works by first copying an executable to the ADMIN$ share of the target machine, which would be logged in
smb_files.log. It then uses the Service Control Manager RPC interface (svcctl) to create a new service (CreateServiceWoperation) that runs the uploaded executable. Therefore, seeing both of these events in Zeek logs is a very strong indicator of PsExec-style lateral movement. An RDP connection is another form of lateral movement but is distinct from PsExec's mechanism. Anepmapperoperation is a generic DCE/RPC lookup and not specific enough. Aconn.logentry for port 445 is expected in an environment using SMB and is not, by itself, a strong indicator of malicious activity. - 2
An intrusion analyst is tasked with writing a Suricata rule to detect potential command-and-control (C2) traffic that uses DNS tunneling. The detection strategy is to flag any DNS query for a TXT record that contains a high-entropy payload, which is characteristic of encoded C2 data. The target domain for this C2 is
*.c2-evil.net. Which rule is crafted most effectively for this purpose?Show answer details
Correct answer: C
This rule is the most effective and precise. It uses Suricata's application-layer parsing (
app-layer-event:dns.query) to specifically target DNS queries. It correctly filters for the query type (dns.query.type:"TXT"), uses the built-in entropy calculation on the queried name (dns.query.name.entropy:>4.5) to identify randomness, and correctly checks if the query ends with the suspected C2 domain (dns.query.name.endswith:".c2-evil.net"). The other options are either too generic, use incorrect syntax, or lack the critical entropy detection component. - 3
During a forensic investigation of a large PCAP file (>50GB), an analyst needs to quickly extract all files transferred over unencrypted HTTP and save them to a directory for malware analysis. The analyst wants to use a command-line tool for efficiency and to script the process for future use. Which
tsharkcommand will accomplish this task most effectively?Show answer details
Correct answer: B
The
--export-objectsflag intsharkis the designated feature for reassembling and exporting objects (files) from various protocols. The syntaxhttp,./extracted_filestellstsharkto extract all objects it can find from the HTTP protocol and save them into theextracted_filesdirectory. This is the most direct, efficient, and reliable command-line method for this task. The other options either extract the wrong data, are syntactically incorrect, or would require significant manual processing to reconstruct the files. - 4
An analyst is reviewing logs from a compromised web server to trace lateral movement. They have access to Zeek's
conn.loganddce_rpc.log. During the incident window, they observe a successful web shell upload followed by an outbound connection from the web server (192.168.10.5) to a domain controller (192.168.10.10) on TCP port 445. Shortly after, the domain controller makes SMB connections to several other critical servers. Which of the following Zeek log entries would provide the strongest evidence of the specific lateral movement technique used? (Select TWO)Show answer details
Correct answer: B, D
The
atsvcendpoint corresponds to the Task Scheduler service. Attackers commonly use this service remotely (e.g., withatorschtasks) to schedule malicious code execution on a target machine, which is a classic lateral movement technique.The
svcctlendpoint is the Service Control Manager. TheCreateServiceWoperation indicates that the source host is attempting to create a new service on the destination. This is a very common and powerful lateral movement technique used by tools like PsExec to run code on remote systems.
