Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 3Objective 1

Analysis of Intelligence GCTI Practice Questions (Page 9)

Part of the Intelligence Analysis and Application domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 9–15 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    An intelligence analyst must produce a product for two different audiences: the SOC team and the executive leadership. The SOC team needs technical details and IOCs, while executives need a high-level summary of risks and recommendations. What is the most appropriate approach?

    Select an answer first
  2. 42expert · hard

    An intelligence team is producing a strategic assessment on the likelihood of a state-sponsored cyber attack. They have limited information and must deliver the assessment in 48 hours. The team has two analysts with different views: one believes the attack is likely, the other believes it is unlikely. What is the most appropriate way to proceed?

    Select an answer first
  3. 43application · medium

    A threat intelligence team has produced a detailed technical analysis of a new exploit. The team needs to inform the executive leadership about the potential business impact. Which type of intelligence product is most appropriate?

    Select an answer first
  4. 44application · medium

    A threat intelligence analyst wants to share a report with a partner organization but is concerned about the sensitivity of the information. The analyst wants to ensure the partner does not share the report with others without permission. What should the analyst do?

    Select an answer first
  5. 45application · medium

    An intelligence analyst receives a request from a law enforcement agency to provide detailed information about a customer's network activity that was captured during a threat investigation. The analyst's organization has a policy that prohibits sharing customer data without a subpoena. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.