
GIAC Cyber Threat Intelligence
Domain 2Objective 1
Collecting and Storing Data Sets GCTI Practice Questions (Page 5)
Part of the Intelligence Collection and Storage domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 21–25
- 21
Which process describes the overall handling of threat intelligence data from initial collection through storage, use, and final deletion?
Select an answer first - 22
A CTI team expects to grow its dataset from 10 million indicators to over 1 billion over the next two years. The team needs to support fast queries for known indicators and also store raw malware samples that are rarely accessed. Which storage architecture should the team choose?
Select an answer first - 23
An organization must decide how long to keep threat intelligence data to support investigations while also complying with legal obligations. What should be established to address this?
Select an answer first - 24
Which security measure is specifically designed to ensure that only authorized personnel can view or modify stored threat intelligence data?
Select an answer first - 25
A CTI team stores threat intelligence data that includes information about vulnerabilities affecting critical infrastructure. Legal counsel advises that certain data must be retained for a minimum of three years for regulatory audits, but the team wants to minimize storage costs. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.