Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 1Objective 1

Intelligence Fundamentals GCTI Practice Questions (Page 8)

Part of the Intelligence Fundamentals domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 36–40

  1. 36application · medium

    A CTI analyst is investigating a phishing campaign targeting the company's finance department. The analyst has access to the full email headers of the phishing messages, the malicious URLs, and the payload hashes. The analyst also has a subscription to a commercial threat intelligence platform that aggregates data from multiple vendors. The analyst needs to determine whether this campaign is linked to a known threat actor. Which combination of sources would provide the STRONGEST evidence for attribution?

    Select an answer first
  2. 37foundation · easy

    What is the key difference between human intelligence (HUMINT) and signals intelligence (SIGINT) in the context of cyber threat intelligence?

    Select an answer first
  3. 38application · medium

    A threat intelligence analyst is investigating a phishing campaign targeting the organization's employees. The analyst has access to email headers from the phishing emails, public reports from security vendors, and internal login logs. The analyst needs to determine the likely motive and sophistication of the threat actor. Which combination of sources would be most effective for this analysis?

    Select an answer first
  4. 39application · medium

    An analyst is investigating a series of data breaches in the healthcare sector. The analyst has access to breach notification reports, a commercial threat intelligence feed, and a vulnerability scanner. The analyst needs to identify the most common initial access vectors used in these breaches. Which source is most appropriate?

    Select an answer first
  5. 40application · medium

    An intelligence analyst has collected data from multiple sources indicating that a known threat actor is targeting the organization's industry. The data includes raw IP addresses, malware hashes, and open-source reports. The analyst must produce a finished intelligence product for the security operations center (SOC) to help them prioritize alerts. What is the most important step the analyst should take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.