
GIAC Cyber Threat Intelligence
Domain 5Objective 1
Pivoting GCTI Practice Questions (Page 4)
Part of the Advanced Analysis Techniques domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 16–20
- 16
Which type of pivoting is most appropriate when an analyst wants to find other indicators that appeared around the same time as a known attack?
Select an answer first - 17
An analyst is pivoting from a known malicious domain to related infrastructure. The pivot returns several IP addresses that host the domain, but one IP is a shared hosting server with hundreds of other domains. How should the analyst treat the domains on that shared server?
Select an answer first - 18
In cyber threat intelligence, what is the primary purpose of pivoting?
Select an answer first - 19
An analyst is pivoting from a known malicious file hash. The hash is found in a public sandbox with a detection ratio of 5/60. The sandbox report shows the file contacted a domain that is registered with privacy protection. The analyst also finds the same file hash in a private threat intel platform with a high-confidence attribution to a known APT group. Which pivot result should the analyst prioritize?
Select an answer first - 20
Which data source would an analyst most likely use to pivot from a file hash to the file's behavior and network indicators?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.