Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 2Objective 1

Collecting and Storing Data Sets GCTI Practice Questions (Page 7)

Part of the Intelligence Collection and Storage domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
8concepts

Questions 31–35

  1. 31application · medium

    A threat intelligence team is building a daily feed of indicators from a mix of open-source malware sandboxes, internal DNS logs, and a commercial threat feed. The team needs to correlate these sources to identify overlapping malicious domains. The data arrives in different formats: JSON, CSV, and proprietary XML. Which approach should the team take to enable consistent correlation?

    Select an answer first
  2. 32application · medium

    A threat intelligence team is establishing a retention policy for different types of data. The team wants to ensure that data is kept long enough for historical analysis but not longer than necessary. What is the best way to determine retention periods?

    Select an answer first
  3. 33expert · hard

    A CTI team shares intelligence with partner organizations. The team wants to ensure that partners can access only the specific indicators they are authorized to see, while also preventing unauthorized internal access. The team uses a cloud-based repository. Which access control approach is most appropriate?

    Select an answer first
  4. 34application · medium

    A CTI team has a dataset of malware hashes and wants to add information about the malware family, associated campaigns, and MITRE ATT&CK techniques. The team has access to a malware analysis platform that provides this context. What should the team do?

    Select an answer first
  5. 35application · medium

    A threat intelligence team has collected IP addresses associated with a botnet. To enhance the intelligence value, the team wants to add geolocation and ownership information to each IP address. What is the best way to achieve this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.