
GIAC Cyber Threat Intelligence
Domain 6Objective 1
Sharing Intelligence GCTI Practice Questions (Page 6)
Part of the Intelligence Sharing domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
5concepts
Questions 26–30
- 26
What is the primary role of an Information Sharing and Analysis Organization (ISAO)?
Select an answer first - 27
A company's threat intelligence team wants to justify participation in an intelligence sharing community to senior management. Which benefit is most directly tied to improving the organization's security posture?
Select an answer first - 28
An organization uses MISP to share intelligence with partners. The SOC wants to automatically block indicators in the firewall but is concerned about false positives causing business disruption. What is the best way to balance automation and risk?
Select an answer first - 29
A security operations center (SOC) receives a STIX 2.1 bundle from a partner organization. The SOC's SIEM cannot natively parse STIX. What is the most efficient way to operationalize the indicators in the SIEM?
Select an answer first - 30
A regional bank is considering joining a financial-sector Information Sharing and Analysis Center (ISAC) to improve its threat visibility. The bank's compliance team is concerned about sharing sensitive indicators with other members. Which approach best addresses the compliance concern while still benefiting from the ISAC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.