
GIAC Cyber Threat Intelligence
Domain 5Objective 2
Campaigns and Attribution GCTI Practice Questions (Page 7)
Part of the Advanced Analysis Techniques domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 31–35
- 31
During a campaign analysis, an analyst maps the observed activities to the campaign lifecycle. The analyst notes that the attackers sent a spear-phishing email with a malicious attachment, which was opened by a user, leading to the installation of a backdoor. The backdoor then established persistence and began collecting credentials. Which stage of the campaign lifecycle is the credential collection activity part of?
Select an answer first - 32
An intelligence team is attributing a campaign to a specific actor. The technical evidence includes a unique malware family and a specific C2 protocol. The operational evidence includes the actor's working hours and the use of a particular VPN provider. The strategic evidence includes the selection of victims in the defense industry. The team is deciding how to combine these evidence types. What is the most appropriate way to use these methodologies together?
Select an answer first - 33
A threat intelligence analyst is documenting a campaign that began with reconnaissance of a target's email system, then used a phishing email to deliver a backdoor, and later moved laterally to a database server. The analyst is describing the campaign lifecycle. Which stage is missing from this description?
Select an answer first - 34
Which of the following is the correct sequence of stages in a typical cyber threat campaign lifecycle?
Select an answer first - 35
An organization has experienced three separate intrusions over six months. Each intrusion used a different malware family and different infrastructure, but all targeted the same type of sensitive data and used similar spear-phishing lures. An analyst is determining whether these are one campaign or three separate campaigns. Which additional evidence would most strongly indicate a single campaign?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.