Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Document preview thumbnail
Aperçu 4 sur 127 pages
Examen

GIAC Cyber Threat Intelligence (GCTI) Exam

Document preview thumbnail
Aperçu 4 sur 127 pages

Tap on **AVAILABLE IN BUNDLE / PACKAGE DEAL** to unlock free bonus exams — save more while getting everything you need. # GIAC Cyber Threat Intelligence (GCTI) Exam Questions and Answers with Detailed Rationales Study Guide The **GIAC Cyber Threat Intelligence (GCTI) Exam Questions and Answers with Detailed Rationales Study Guide** is a focused preparation resource for cybersecurity professionals preparing for the **GIAC Cyber Threat Intelligence (GCTI) Certification Exam**. The guide focuses on the most important areas, including **cyber threat intelligence fundamentals, intelligence requirements, intelligence lifecycle, threat actors, adversary tactics and techniques, indicators of compromise, intelligence collection, analysis, attribution, threat hunting, reporting, and intelligence-driven security operations**. Major emphasis is placed on **cyber threat intelligence fundamentals**, including the purpose of intelligence, strategic, operational, tactical, and technical intelligence, intelligence requirements, collection priorities, intelligence consumers, confidence levels, and applying intelligence to cybersecurity decisions. The material covers the **threat intelligence lifecycle**, including planning and direction, collection, processing, analysis, dissemination, feedback, and continuous improvement of intelligence products. Special attention is given to **threat actors and adversary behavior**, including motivations, capabilities, resources, targeting patterns, attack infrastructure, persistence techniques, operational objectives, and distinguishing between different types of threat actors. The guide emphasizes **adversary tactics, techniques, and procedures (TTPs)**, including recognizing attacker behavior, mapping activity to established frameworks, identifying patterns across incidents, and using behavioral information to improve detection and response. Major topics include **indicators of compromise and indicators of attack**, including IP addresses, domains, URLs, file hashes, malware artifacts, email indicators, registry changes, process activity, network behavior, and understanding the limitations of relying only on static indicators. The material also addresses **intelligence collection and data sources**, including open-source intelligence, internal security telemetry, network data, endpoint information, malware analysis, vulnerability information, security reports, dark-web intelligence, and other relevant sources. The guide covers **intelligence analysis techniques**, including correlation, link analysis, hypothesis development, pattern recognition, contextual analysis, confidence assessment, source evaluation, identifying intelligence gaps, and separating facts from assumptions. The study material emphasizes **threat hunting and detection**, including developing intelligence-driven hunting hypotheses, identifying suspicious behavior, correlating threat intelligence with security telemetry, detecting adversary activity, and using intelligence to improve defensive controls. The guide also addresses **threat intelligence reporting and dissemination**, including intelligence briefs, technical reports, executive reporting, audience-specific communication, prioritization, actionable recommendations, confidence statements, and presenting intelligence in a clear and useful format. The study guide includes **original exam-style questions with correct answers and detailed rationales** covering realistic GCTI scenarios involving cyber threat intelligence concepts, intelligence requirements, threat actors, TTPs, indicators, collection, analysis, attribution, threat hunting, intelligence reporting, and applying intelligence to cybersecurity operations.

Aperçu du contenu

GIAC Cyber Threat Intelligence (GCTI) Exam

Exam Coverage


1. Threat Intelligence Fundamentals — intelligence lifecycle, strategic/operational/tactical

intelligence, requirements, indicators, context, confidence, and intelligence value.


2. Intelligence Analysis — analytic methods, hypotheses, sourcing, confidence, uncertainty,

cognitive bias, fallacies, assumptions, and structured analytical techniques.


3. OSINT and Campaign Analysis — public sources, collection planning, campaign profiling,

intrusion characteristics, timelines, infrastructure, and external intelligence.


4. Attribution — evidence-based attribution, competing hypotheses, infrastructure reuse,

tooling, behaviors, victimology, false flags, and confidence levels.


5. Collection and Data Sets — threat feeds, domains, IP addresses, TLS certificates, DNS,

WHOIS/RDAP, logs, forensic artifacts, and data quality.

6. Kill Chain, Diamond Model, and Courses of Action — intrusion mapping, adversary

capabilities, infrastructure, victims, events, and defensive response options.


7. Malware Intelligence — static and behavioral analysis, sandboxing, hashes, strings,

configuration extraction, malware infrastructure, and intelligence pivots.


8. Pivoting and Domain Analysis — relationships among domains, certificates, IPs, registrars,

passive DNS, hosting, subdomains, and linked infrastructure.


9. Intelligence Sharing and Reporting — STIX/TAXII concepts, intelligence products,

assessments, executive reporting, tactical dissemination, and information handling.

,10. Intelligence Application and Threat-Informed Defense — applying intelligence to detection,

hunting, prioritization, risk decisions, incident response, and defensive planning.



Questions


1. While investigating related intrusion activity, Which observation can be especially useful

when investigating whether several domains may share common infrastructure over time?


A. Historical DNS resolution


B. Current keyboard layout


C. Screen brightness


D. File compression ratio


Answer: A

Rationale: Historical DNS information can reveal infrastructure relationships that are no longer

visible from current records.


2. For an analyst working on an active investigation, A vulnerability is actively exploited by an

adversary targeting the organization's technology stack. How can threat intelligence improve

prioritization?


A. Connect exploitation evidence with organizational exposure


B. Treat every vulnerability equally


C. Ignore business context


D. Only examine vendor marketing

,Answer: A

Rationale: Threat intelligence can help prioritize vulnerabilities by connecting adversary activity

to the organization's actual exposure and risk.


3. For an analyst working on an active investigation, Which observation can be especially useful

when investigating whether several domains may share common infrastructure over time?


A. Historical DNS resolution


B. Current keyboard layout


C. Screen brightness


D. File compression ratio


Answer: A

Rationale: Historical DNS information can reveal infrastructure relationships that are no longer

visible from current records.


4. When reviewing collected evidence, Why is source reliability important when analysts

combine information from several intelligence feeds into one assessment?


A. Poor sources can weaken the assessment


B. Reliable sources eliminate uncertainty


C. Source reliability proves attribution


D. Source reliability replaces analysis


Answer: A

, Rationale: Source reliability affects how much confidence analysts should place in collected

information.


5. For an analyst working on an active investigation, A vulnerability is actively exploited by an

adversary targeting the organization's technology stack. How can threat intelligence improve

prioritization?


A. Connect exploitation evidence with organizational exposure


B. Treat every vulnerability equally


C. Ignore business context


D. Only examine vendor marketing


Answer: A

Rationale: Threat intelligence can help prioritize vulnerabilities by connecting adversary activity

to the organization's actual exposure and risk.


6. During a threat intelligence investigation, A malware sample is executed in a controlled

environment to observe files, processes, network connections, and registry changes. What

technique is being used?


A. Behavioral analysis


B. Password cracking


C. Certificate transparency


D. Social engineering

Infos sur le Document

Publié le
22 août 2026
Nombre de pages
127
Écrit en
2026/2027
Type
Examen
Contient
Questions et réponses
$34.99

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
STUVIAGRADES
4.8
(1066)
Vendu
6652
Abonnés
467
Éléments
9116
Dernière vente
2 jours de cela



Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Vous travaillez sur vos références ?

Créez des citations précises en APA, MLA et Harvard avec notre générateur de sources gratuit.

Vous travaillez sur vos références ?

Foire aux questions