
GIAC Cyber Threat Intelligence
Domain 5Objective 1
Pivoting GCTI Practice Questions (Page 7)
Part of the Advanced Analysis Techniques domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 31–35
- 31
An analyst has a malware sample and wants to find other samples from the same threat actor. The analyst decides to pivot using the sample's unique embedded string. What is the primary advantage of this pivot over using the sample's file hash?
Select an answer first - 32
An analyst pivots from a domain to an IP using passive DNS data. Why might the resulting IP be inaccurate?
Select an answer first - 33
Which data source is most commonly used to pivot from a domain name to the IP address it resolves to?
Select an answer first - 34
What should be included in the documentation of a pivot chain to support reproducibility?
Select an answer first - 35
An analyst is investigating a series of attacks that occurred every Tuesday for three weeks. Each attack used a different IP address and domain, but the malware samples are identical. Which pivot type would be most effective to link the attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.