Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 3Objective 2

Intelligence Application GCTI Practice Questions (Page 8)

Part of the Intelligence Analysis and Application domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 9–15 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 36–40

  1. 36expert · hard

    A multinational company has a security team that produces threat intelligence for both its internal SOC and its customers. The team has limited resources and must decide how to allocate effort between producing a detailed report on a new adversary group targeting the company's sector and updating existing detection rules for a previously identified group that is still active. The SOC has reported that the existing rules are generating a high number of false positives. Which decision best balances the competing needs?

    Select an answer first
  2. 37expert · hard

    A threat intelligence team is preparing to disseminate a report on a zero-day vulnerability affecting a widely used VPN product. The report includes technical details, exploit code, and recommended mitigations. The team must decide how to share this information with different stakeholders, including the vendor, customers, and the public. Which dissemination strategy best balances responsible disclosure and stakeholder needs?

    Select an answer first
  3. 38application · medium

    After a major incident, the CTI team reviews the intelligence products they produced during the event. The SOC analysts report that the daily threat briefs were too generic and did not include the specific IOCs they needed for detection. The CTI lead wants to improve future intelligence products. Which action best incorporates this feedback?

    Select an answer first
  4. 39application · medium

    During incident response, the CTI team provides intelligence that a threat actor typically exfiltrates data via encrypted DNS tunnels. The IR team is unsure how to use this information. Which action best applies the intelligence to the response?

    Select an answer first
  5. 40application · medium

    A threat intelligence team has been producing monthly reports for the executive team. After several months, the executives indicate that the reports are too technical and do not clearly communicate business risk. Which action best addresses this feedback?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.