Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 1Objective 1

Intelligence Fundamentals GCTI Practice Questions (Page 5)

Part of the Intelligence Fundamentals domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 21–25

  1. 21application · medium

    A threat intelligence team has produced a report on a new malware campaign. The report is intended for both the executive team and the SOC. The team has limited time and must disseminate the report. What is the best approach?

    Select an answer first
  2. 22application · medium

    A financial services firm has just experienced a ransomware attack that disrupted trading operations for six hours. The board has approved a new threat intelligence program and wants to ensure that future attacks are detected earlier. The CTI team is defining the first intelligence cycle. Which action should the team take FIRST to ensure the cycle produces actionable results?

    Select an answer first
  3. 23application · medium

    A cyber threat intelligence team is tasked with producing a quarterly report for the board of directors. The report must summarize the top threats facing the organization and justify the security budget. The team has collected a large volume of raw data from multiple sources, but the analysts are overwhelmed and the report is due in two weeks. Which step of the intelligence lifecycle should the team prioritize to ensure the report is useful and delivered on time?

    Select an answer first
  4. 24expert · medium

    A CTI team is establishing a new intelligence capability. The team has limited budget and must choose between two collection strategies: (1) purchasing a commercial threat intelligence feed that provides a high volume of indicators, or (2) building a small internal team that conducts targeted collection based on the organization's specific intelligence requirements. The organization's primary need is to support incident response for a specific set of critical assets. Which strategy is MOST aligned with the intelligence cycle and the organization's need?

    Select an answer first
  5. 25application · medium

    A threat intelligence team is tasked with supporting a new product launch. The product team is concerned about intellectual property theft. The security team has limited collection resources. Which intelligence requirement is most appropriate to guide collection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.