
GIAC Cyber Threat Intelligence
Domain 5Objective 2
Campaigns and Attribution GCTI Practice Questions (Page 3)
Part of the Advanced Analysis Techniques domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 11–15
- 11
An organization has experienced three separate security incidents over the past six months. In each incident, the attackers used a different malware family and a different initial access vector (one via phishing, one via exploitation of a public-facing application, and one via credential stuffing). However, in all three incidents, the attackers used the same custom post-exploitation toolkit and exfiltrated data to the same external IP address. How should the organization's threat intelligence team characterize these incidents?
Select an answer first - 12
A security operations center has observed multiple alerts over the past month: a phishing email with a specific subject line, a malware hash, and a command-and-control domain. The analyst wants to determine if these alerts are part of the same campaign. Which action would most effectively support that determination?
Select an answer first - 13
An analyst at a manufacturing firm notices that a single phishing email led to a credential compromise, followed by a separate ransomware deployment three weeks later. The analyst wants to determine whether these two events should be treated as one campaign or two unrelated incidents. Which combination of evidence would most strongly support treating them as a single campaign?
Select an answer first - 14
An incident response team discovers that a ransomware campaign uses a wiper disguised as ransomware and that the decryption key is absent. The malware contains strings in Russian, and the C2 infrastructure is hosted in a country that is a known adversary of Russia. The team is considering attribution. What is the most important consideration before concluding the actor is Russian?
Select an answer first - 15
An intelligence team has attributed a campaign to a specific threat actor based on a single piece of malware that shares a rare code signature with a known sample. The team is preparing a report for executives. How should the team communicate the confidence level of this attribution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.