
GIAC Cyber Threat Intelligence
Domain 3Objective 1
Analysis of Intelligence GCTI Practice Questions (Page 5)
Part of the Intelligence Analysis and Application domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 9–15 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 21–25
- 21
An analyst is reviewing a set of IOCs from a threat intelligence feed. One IOC is a domain that has been observed in multiple unrelated campaigns. Another IOC is a unique file hash. The analyst must prioritize which IOC to use for detection. What is the most appropriate decision?
Select an answer first - 22
Which type of intelligence product is typically a short, time-sensitive document that provides immediate warning of a developing threat or incident?
Select an answer first - 23
In intelligence analysis, what does the confidence level of a judgment represent?
Select an answer first - 24
An analyst is profiling a threat actor that has been observed using a mix of sophisticated and unsophisticated techniques. The actor has targeted both large enterprises and small businesses. The analyst must determine the actor's likely motivation. Which evidence would be most indicative of a financially motivated actor?
Select an answer first - 25
A cybersecurity team wants to share threat intelligence with a partner organization. The intelligence includes sensitive details about a vulnerability in a third-party product that is not yet patched. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.