
GIAC Cyber Threat Intelligence
Domain 5Objective 2
Campaigns and Attribution GCTI Practice Questions (Page 6)
Part of the Advanced Analysis Techniques domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 26–30
- 26
A threat intelligence team is attributing a campaign that uses a known malware family but with a new obfuscation layer. The team has three hypotheses: a known APT group, a copycat using leaked source code, or a false flag by a different actor. The team has limited time and resources. Which approach best balances analytical rigor and resource constraints?
Select an answer first - 27
A threat intelligence team has gathered the following evidence about a campaign: (1) the malware shares a unique code signing certificate with a known actor, (2) the C2 infrastructure overlaps with infrastructure previously used by that actor, and (3) the TTPs match the actor's known playbook. However, the team has not identified the motive behind the campaign. How should the team communicate attribution confidence?
Select an answer first - 28
An analyst is reviewing multiple security incidents that occurred over the past year. The analyst notices that several incidents share the same malicious IP address for C2 communications, but the malware families are different. Additionally, the phishing emails in each incident use different lures and are sent from different email accounts. What is the most appropriate use of the shared IP address in this context?
Select an answer first - 29
During a campaign analysis, an analyst is mapping the observed activities to the campaign lifecycle. The analyst notes that the attackers conducted extensive open-source intelligence gathering on the target organization's employees, then crafted a spear-phishing email using information from social media. After the email was opened, the attackers exploited a vulnerability in the email client to gain initial access. Which stages of the campaign lifecycle are represented by these activities?
Select an answer first - 30
An analyst is examining a campaign that uses malware with code that is identical to a known state-sponsored actor's malware, but the C2 infrastructure is hosted in a country that is a known adversary of that state. Additionally, the malware contains a unique string that appears to be a reference to a different threat actor. The analyst is considering whether this is a false flag operation. What is the most appropriate conclusion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.