Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 4Objective 1

Kill Chain, Diamond Model, and Courses of Action Matrix GCTI Practice Questions (Page 5)

Part of the Operational Frameworks and Models domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 6–11 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
10concepts

Questions 21–25

  1. 21application · medium

    An analyst is documenting a cyber event using the Diamond Model. The event involved a phishing email that delivered a remote access trojan (RAT). The RAT connected to a server hosted on a bulletproof hosting provider. The victim was a specific employee at a financial institution. Which of the following is the correct classification of the bulletproof hosting server?

    Select an answer first
  2. 22foundation · easy

    What is the primary purpose of the cyber kill chain model in threat intelligence?

    Select an answer first
  3. 23expert · hard

    A threat intelligence team is analyzing an intrusion where the adversary used a previously unknown malware variant to establish persistence on a victim's workstation. The team has identified the C2 infrastructure and the victim. They need to develop a response strategy that both disrupts the adversary's current operations and degrades their ability to use the same infrastructure in the future. Which combination of courses of action is most appropriate?

    Select an answer first
  4. 24foundation · easy

    Which COA category is focused on making an adversary's tools or techniques less effective, such as throttling bandwidth to slow data exfiltration?

    Select an answer first
  5. 25application · medium

    During an incident response, an analyst observes the following sequence: an attacker scanned the network for open ports, sent a phishing email with a malicious link, the victim clicked the link and downloaded malware, the malware beaconed to an external server, and then the attacker used the compromised host to access a file share. Which two kill chain stages are most directly demonstrated by the scanning and the file share access?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.