
GIAC Cyber Threat Intelligence
Domain 6Objective 1
Sharing Intelligence GCTI Practice Questions (Page 10)
Part of the Intelligence Sharing domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
5concepts
Questions 46–48
- 46
A security operations center (SOC) uses MISP to share and correlate threat intelligence with partner organizations. The SOC wants to automatically enrich their SIEM alerts with context from MISP, such as related campaigns and attack patterns. What is the most effective way to achieve this integration?
Select an answer first - 47
A SOC receives a MISP event containing a YARA rule for a new malware family. The SOC wants to use this rule to detect the malware on endpoints. What is the most appropriate action?
Select an answer first - 48
Which of the following is a characteristic of an Information Sharing and Analysis Center (ISAC)?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCTI
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.