Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Threat Intelligence

Domain 6Objective 1

Sharing Intelligence GCTI Practice Questions (Page 7)

Part of the Intelligence Sharing domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 8–14 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
5concepts

Questions 31–35

  1. 31application · medium

    A security analyst at a mid-sized company wants to share a new malware signature with a peer organization that uses a different SIEM platform. The analyst has the malware's file hash, C2 domain, and a YARA rule. Which approach best enables automated, structured sharing between the two organizations?

    Select an answer first
  2. 32expert · hard

    A multinational corporation participates in an ISAO that shares threat intelligence across industries. The ISAO's sharing agreement includes a 'safe harbor' clause that protects members from liability when sharing indicators in good faith. The corporation's legal team is concerned about sharing data that may include personal information of customers. The security team wants to share a set of IP addresses and domain names associated with a recent phishing campaign. What is the most appropriate action?

    Select an answer first
  3. 33application · medium

    A government agency wants to share threat intelligence with private sector companies in critical infrastructure sectors. Which model is most appropriate for this public-private collaboration?

    Select an answer first
  4. 34expert · medium

    A large enterprise receives a high-volume STIX feed from an ISAC. The SOC wants to use this feed to block malicious IPs at the firewall, but the firewall has a limited rule capacity. The feed contains many IPs with varying confidence levels. What is the best approach to maximize protection while avoiding firewall rule exhaustion?

    Select an answer first
  5. 35application · medium

    A company receives a TAXII feed with indicators of a new exploit kit. The security team wants to use this intelligence to proactively block the exploit kit's delivery domains. What is the most effective way to operationalize this intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTI” is a trademark of its owner, used for identification only.