
GIAC Information Security Fundamentals
Domain 3Objective 1
Adversary Analysis and Threat Frameworks GISF Practice Questions (Page 5)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 21–25
- 21
An incident response team is reviewing a breach where the attacker used a previously unknown exploit for a zero-day vulnerability, then used native Windows tools to move laterally, and finally encrypted files and demanded a ransom. The team wants to improve detection for future incidents. Which approach would be most effective?
Select an answer first - 22
A threat intelligence team has collected raw data from various sources, including open-source feeds, internal logs, and industry reports. They have converted the data into a standardized format and are now analyzing it to identify patterns and produce actionable intelligence. Which stage of the threat intelligence lifecycle are they currently in?
Select an answer first - 23
What is a 'false flag' in the context of cyber attack attribution?
Select an answer first - 24
A security operations team is investigating a potential compromise. They have identified a suspicious process running on a server that is making outbound connections to an IP address that is not on any threat intelligence feed. The process name is similar to a legitimate Windows service. What should the team do to determine if this is a true indicator of compromise?
Select an answer first - 25
A government contractor has discovered that a foreign intelligence service has been attempting to steal classified project information. The attacks are highly sophisticated, use custom malware, and are persistent over many months. The contractor wants to implement defensive countermeasures. Which approach is most appropriate for this threat actor type?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.