
GIAC Cyber Threat Intelligence
Domain 2Objective 2
Malware as a Collection Source GCTI Practice Questions (Page 4)
Part of the Intelligence Collection and Storage domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 16–20
- 16
In cyber threat intelligence, what is the primary role of malware as a collection source?
Select an answer first - 17
An intelligence analyst has finished analyzing a new backdoor and has identified several indicators, including a unique mutex name, a C2 domain, and a specific registry key it creates. Which of the following is the most effective way to package these indicators for use by the security operations center?
Select an answer first - 18
After analyzing a ransomware sample, an intelligence analyst identifies a unique hardcoded wallet address and a specific file-extension pattern used by the malware. Which of the following is the most actionable intelligence product for network defenders?
Select an answer first - 19
An analyst is examining a worm that spreads via USB drives. The analyst needs to identify the worm's propagation method and any files it drops. Which combination of analysis techniques would be most effective?
Select an answer first - 20
Which malware type is most valuable for understanding an adversary's data exfiltration techniques?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.