Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 3Objective 1

Analysis of Intelligence GCTI Practice Questions (Page 3)

Part of the Intelligence Analysis and Application domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 9–15 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    Which of the following is a common standard used to structure and share cyber threat intelligence in a machine-readable format?

    Select an answer first
  2. 12expert · hard

    An intelligence analyst is preparing a report that includes information about a vulnerability in a widely used product. The analyst's organization has a policy that requires responsible disclosure. The analyst has discovered that the vendor has not responded to multiple notifications. What is the most ethical course of action?

    Select an answer first
  3. 13application · medium

    An analyst is building a threat actor profile for a group that has targeted financial institutions in Southeast Asia. The group uses publicly available exploit kits and sends phishing emails with themes related to regional banking regulations. They operate during business hours in the UTC+7 timezone. What is the most defensible conclusion about this group's capability and intent?

    Select an answer first
  4. 14application · medium

    A security analyst discovers a suspicious file on a server. The analyst extracts a hash, a domain, and an IP address from the file's behavior. Which of these IOCs is most likely to be a reliable indicator of compromise for detecting this specific malware?

    Select an answer first
  5. 15application · medium

    During incident response, an analyst discovers a unique domain name used for command-and-control (C2) and a unique malware hash. The C2 domain is registered with a privacy service. The analyst must produce an intelligence report for the SOC team. What is the most appropriate way to present these IOCs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.