Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 1Objective 1

Intelligence Fundamentals GCTI Practice Questions (Page 6)

Part of the Intelligence Fundamentals domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 26–30

  1. 26application · medium

    A CTI analyst has collected data on a phishing campaign that targets the company's employees. The data includes the phishing email content, the malicious URLs, and the payload hashes. The analyst needs to produce an intelligence product that will help the company's security awareness team improve training. Which type of product would be MOST useful for this purpose?

    Select an answer first
  2. 27application · medium

    A small company has a mature security operations team but no formal CTI capability. The team occasionally reads threat reports from vendors and government agencies. The company is considering whether to invest in a formal CTI program. Which outcome would BEST demonstrate the value of a formal CTI program?

    Select an answer first
  3. 28application · medium

    A threat intelligence analyst has identified a new phishing kit being sold on a dark web forum. The analyst has the kit's source code and a list of domains used in recent campaigns. The analyst needs to produce a product that will help the organization's email security team block these campaigns. What is the most useful product?

    Select an answer first
  4. 29application · medium

    A small company has a limited security budget and no dedicated threat intelligence team. The CEO asks the IT manager to 'start doing threat intelligence' to reduce the risk of a data breach. The IT manager has access to a commercial threat intelligence feed and a basic SIEM. What is the most appropriate first step to build a sustainable threat intelligence capability?

    Select an answer first
  5. 30application · medium

    A threat intelligence analyst is preparing a briefing for senior management about a new ransomware group. The analyst has collected technical indicators, victimology data, and open-source reporting. The briefing must help management understand the potential impact on the organization and decide whether to invest in additional defenses. Which type of intelligence product is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.