Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 3Objective 2

Intelligence Application GCTI Practice Questions (Page 2)

Part of the Intelligence Analysis and Application domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 9–15 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 6–10

  1. 6expert · hard

    A multinational organization's CTI team produces a threat report on a sophisticated adversary. The report includes sensitive source information that cannot be shared broadly, but the organization's regional security teams need actionable indicators. The CTI lead must balance the need for timely dissemination with the protection of sources. Which approach best satisfies both requirements?

    Select an answer first
  2. 7expert · hard

    A CTI team has intelligence that a threat actor is likely to use a specific remote access tool (RAT) in the next campaign. The organization's security team is considering whether to block the RAT's known domains or to focus on detecting the RAT's behavior. The team has limited resources and must choose a strategy. Which approach is most effective given the intelligence?

    Select an answer first
  3. 8expert · hard

    A CTI team receives feedback that their weekly threat briefs are too long and not read by the SOC. The SOC prefers a short, actionable summary with IOCs. However, the executive team wants a monthly strategic report. The CTI lead must redesign the dissemination process with limited resources. Which approach best addresses the feedback while using resources efficiently?

    Select an answer first
  4. 9application · medium

    A cyber threat intelligence team has produced a detailed report on a new ransomware family that targets backup systems. The report includes technical indicators, MITRE ATT&CK mappings, and recommended mitigations. Which dissemination approach best ensures the report is actionable for both technical and non-technical stakeholders?

    Select an answer first
  5. 10expert · hard

    A threat intelligence team has been providing weekly reports to the security operations center (SOC). The SOC has provided feedback that the reports are often too late to be actionable, and that the team would prefer real-time alerts for critical indicators. The intelligence team has limited automation capabilities. Which action best addresses the feedback while considering the team's constraints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.