
GIAC Open Source Intelligence (GOSI)
Domain 1Objective 1
OSINT Methodology GOSI Practice Questions (Page 5)
Part of the OSINT Fundamentals and Methodology domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 21–25
- 21
An analyst is compiling a report on a company's data breach. The analyst has three sources: a tweet from an unknown user, a blog post from a cybersecurity researcher, and an official statement from the company. The tweet and blog post agree on the breach, but the company denies it. What is the most appropriate way to present this in the report?
Select an answer first - 22
An analyst is investigating a suspected money laundering operation. The analyst needs to find corporate registrations, property ownership, and court records. Which category of OSINT sources is most appropriate?
Select an answer first - 23
An OSINT analyst has produced a report on a potential supply chain vulnerability. The report includes a detailed analysis and recommendations. The client requests that the report be shortened to one page for executive review. What is the best approach?
Select an answer first - 24
An OSINT analyst is preparing a final report for a client. The report should be actionable and clear. Which elements should be included in the report? Select all that apply.
Select an answer first - 25
What is a key characteristic of an effective OSINT report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOSI” is a trademark of its owner, used for identification only.