
GIAC Cyber Threat Intelligence
Domain 2Objective 1
Collecting and Storing Data Sets GCTI Practice Questions (Page 8)
Part of the Intelligence Collection and Storage domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 36–40
- 36
An analyst combines threat data from internal logs with external OSINT feeds and adds context such as the threat actor's motivation. What is this process called?
Select an answer first - 37
A CTI team ingests a large number of indicators from an automated feed. The team discovers that some indicators are outdated (e.g., IP addresses that are no longer malicious) and some are incorrectly formatted. What is the best way to maintain the quality of the indicator database?
Select an answer first - 38
In data lifecycle management, what is the final stage of data handling for data that is no longer needed?
Select an answer first - 39
A CTI team collects a list of malicious IP addresses from a sandbox feed. The team wants to add geolocation, ASN ownership, and historical WHOIS data to each IP to help prioritize incidents. Which process should the team use?
Select an answer first - 40
What is the goal of data quality management in a threat intelligence dataset?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.