Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Fundamentals

Domain 3Objective 1

Adversary Analysis and Threat Frameworks GISF Practice Questions (Page 9)

Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 41–45

  1. 41expert · hard

    A security team is analyzing an intrusion where the attacker used a sophisticated zero-day exploit, custom malware, and operational security measures such as Tor and encrypted communications. The malware sample contains code strings in Russian and was also used in a previous campaign attributed to a known cybercriminal group. However, the attack's sophistication suggests possible nation-state involvement. The team must decide how to report attribution to management. Which approach is most appropriate?

    Select an answer first
  2. 42expert · hard

    A company is threat modeling a new payment processing system. The team has limited resources and must prioritize which threats to address. They have identified the following threats: (A) an attacker could steal credit card data in transit, (B) an attacker could tamper with transaction amounts, (C) an attacker could cause a denial of service, and (D) an attacker could impersonate a legitimate user. The team wants to use DREAD to prioritize these threats. Which threat would likely receive the highest overall DREAD score?

    Select an answer first
  3. 43application · medium

    A security analyst is investigating a breach and finds that the attacker used a VPN service, leveraged a publicly available exploit kit, and left behind a malware sample that shares code with a known cybercriminal group's tools. The analyst is preparing a report for management. Which statement best reflects the appropriate conclusion about attribution?

    Select an answer first
  4. 44expert · hard

    A security team is profiling potential adversaries for a defense contractor that handles classified projects. The team has identified the following threat actors: (A) a nation-state with advanced cyber capabilities, (B) a hacktivist group opposed to the company's projects, (C) a cybercriminal syndicate seeking financial gain, and (D) a disgruntled employee with access to sensitive data. The company must prioritize its defenses based on the most likely and impactful threats. Which actor should be the primary focus?

    Select an answer first
  5. 45expert · hard

    A threat intelligence team is building a new intelligence program. They have limited staff and budget. They need to decide which sources to prioritize for collection. The team has access to: (1) open-source threat feeds, (2) a commercial threat intelligence subscription, (3) internal logs from their own network, and (4) information sharing partnerships with other organizations in their sector. Which combination of sources would provide the most balanced and actionable intelligence for their organization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.