Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?

⚠ Common exam trap

Test-takers sometimes mistake high-volume traffic to a single destination port for a port scan, missing the core definition of scanning multiple ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A high frequency of connection attempts from one source to many destination ports.

A port scan involves a single source IP attempting to connect to a large range of destination ports in a short timeframe. Firewall logs showing a spike in 'Denied' or 'Dropped' connection attempts from one host to many different targets is a classic signature. Identifying this helps analysts catch reconnaissance activity early before the attacker transitions to active exploitation of a specific vulnerable service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple successful inbound connections to port 80.

    Why it's wrong here

    Multiple successful connections to port 80 usually indicate normal web traffic or potentially a DoS/DDoS event. Port scanning is characterized by failed or rejected connection attempts, not successful ones. This activity represents standard web consumption or high-volume traffic rather than the systematic probing associated with network reconnaissance.

  • ✓

    A high frequency of connection attempts from one source to many destination ports.

    Why this is correct

    Systematic probes across a large range of ports from a single source are the primary indicator of a port scan. Security analysts use this pattern to identify reconnaissance efforts, allowing them to block the offending IP address before the attacker can identify and exploit vulnerable services on the network.

  • ✗

    A single connection to a database port from an internal host.

    Why it's wrong here

    A single connection is normal behavior for an application server accessing its database. It does not exhibit the characteristics of a scan, which requires high volume and breadth. This is likely routine operational traffic and should not be flagged as an indicator of malicious reconnaissance activity.

  • ✗

    Periodic outbound traffic to a known DNS server.

    Why it's wrong here

    Periodic DNS lookups are expected behavior for any system maintaining network connectivity. This traffic is essential for name resolution and does not indicate malicious scanning. Flagging this would generate significant false positives, distracting analysts from actual malicious reconnaissance efforts that follow a different and more aggressive pattern.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.