
GIAC Cloud Threat Detection
Domain 3Objective 2
Cyber Threat Intelligence for the Cloud GCTD Practice Questions (Page 1)
Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 1–5
- 1
A cloud security analyst at a financial institution is considering joining a threat intelligence sharing community. The analyst wants to share indicators of compromise with other organizations while maintaining regulatory compliance and protecting sensitive data. Which action is most appropriate?
Select an answer first - 2
In cloud incident response, how can CTI support threat hunting?
Select an answer first - 3
A cloud security analyst is explaining the role of CTI to a new team member. The analyst wants to emphasize how CTI differs from general security awareness. Which statement best highlights this difference?
Select an answer first - 4
Which of the following is an example of a threat intelligence sharing organization relevant to cloud security?
Select an answer first - 5
A security team is reviewing a recent incident where an attacker exploited a misconfigured S3 bucket to exfiltrate data. The team wants to understand the threat actor's motivation and improve detection. Which combination of threat actor profile and cloud-specific TTP is most relevant?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.