
GIAC Cyber Threat Intelligence
Domain 3Objective 2
Intelligence Application GCTI Practice Questions (Page 5)
Part of the Intelligence Analysis and Application domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 9–15 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 21–25
- 21
A CTI team has just completed a comprehensive report on a ransomware group's TTPs. The team wants to ensure the intelligence is applied effectively across the organization. Which action best fulfills the purpose of intelligence application?
Select an answer first - 22
Which of the following best describes how intelligence is integrated into security operations?
Select an answer first - 23
A CTI team must disseminate a time-sensitive warning about an active exploitation campaign to multiple stakeholders, including executives, SOC analysts, and system administrators. The warning contains sensitive details about a zero-day vulnerability. Which dissemination strategy best balances timeliness, actionability, and security?
Select an answer first - 24
A CTI team's quarterly intelligence report is consistently rated as 'not actionable' by the SOC and 'too technical' by the executive team. The CTI lead must redesign the reporting process. Which change best addresses the feedback from both audiences?
Select an answer first - 25
Why is the intelligence application phase considered a critical part of the cyber threat intelligence lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.