Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 127 pages
Exam (elaborations)

GIAC Cyber Threat Intelligence (GCTI) Exam

Document preview thumbnail
Preview 4 out of 127 pages

Tap on **AVAILABLE IN BUNDLE / PACKAGE DEAL** to unlock free bonus exams — save more while getting everything you need. # GIAC Cyber Threat Intelligence (GCTI) Exam Questions and Answers with Detailed Rationales Study Guide The **GIAC Cyber Threat Intelligence (GCTI) Exam Questions and Answers with Detailed Rationales Study Guide** is a focused preparation resource for cybersecurity professionals preparing for the **GIAC Cyber Threat Intelligence (GCTI) Certification Exam**. The guide focuses on the most important areas, including **cyber threat intelligence fundamentals, intelligence requirements, intelligence lifecycle, threat actors, adversary tactics and techniques, indicators of compromise, intelligence collection, analysis, attribution, threat hunting, reporting, and intelligence-driven security operations**. Major emphasis is placed on **cyber threat intelligence fundamentals**, including the purpose of intelligence, strategic, operational, tactical, and technical intelligence, intelligence requirements, collection priorities, intelligence consumers, confidence levels, and applying intelligence to cybersecurity decisions. The material covers the **threat intelligence lifecycle**, including planning and direction, collection, processing, analysis, dissemination, feedback, and continuous improvement of intelligence products. Special attention is given to **threat actors and adversary behavior**, including motivations, capabilities, resources, targeting patterns, attack infrastructure, persistence techniques, operational objectives, and distinguishing between different types of threat actors. The guide emphasizes **adversary tactics, techniques, and procedures (TTPs)**, including recognizing attacker behavior, mapping activity to established frameworks, identifying patterns across incidents, and using behavioral information to improve detection and response. Major topics include **indicators of compromise and indicators of attack**, including IP addresses, domains, URLs, file hashes, malware artifacts, email indicators, registry changes, process activity, network behavior, and understanding the limitations of relying only on static indicators. The material also addresses **intelligence collection and data sources**, including open-source intelligence, internal security telemetry, network data, endpoint information, malware analysis, vulnerability information, security reports, dark-web intelligence, and other relevant sources. The guide covers **intelligence analysis techniques**, including correlation, link analysis, hypothesis development, pattern recognition, contextual analysis, confidence assessment, source evaluation, identifying intelligence gaps, and separating facts from assumptions. The study material emphasizes **threat hunting and detection**, including developing intelligence-driven hunting hypotheses, identifying suspicious behavior, correlating threat intelligence with security telemetry, detecting adversary activity, and using intelligence to improve defensive controls. The guide also addresses **threat intelligence reporting and dissemination**, including intelligence briefs, technical reports, executive reporting, audience-specific communication, prioritization, actionable recommendations, confidence statements, and presenting intelligence in a clear and useful format. The study guide includes **original exam-style questions with correct answers and detailed rationales** covering realistic GCTI scenarios involving cyber threat intelligence concepts, intelligence requirements, threat actors, TTPs, indicators, collection, analysis, attribution, threat hunting, intelligence reporting, and applying intelligence to cybersecurity operations.

Content preview

GIAC Cyber Threat Intelligence (GCTI) Exam

Exam Coverage


1. Threat Intelligence Fundamentals — intelligence lifecycle, strategic/operational/tactical

intelligence, requirements, indicators, context, confidence, and intelligence value.


2. Intelligence Analysis — analytic methods, hypotheses, sourcing, confidence, uncertainty,

cognitive bias, fallacies, assumptions, and structured analytical techniques.


3. OSINT and Campaign Analysis — public sources, collection planning, campaign profiling,

intrusion characteristics, timelines, infrastructure, and external intelligence.


4. Attribution — evidence-based attribution, competing hypotheses, infrastructure reuse,

tooling, behaviors, victimology, false flags, and confidence levels.


5. Collection and Data Sets — threat feeds, domains, IP addresses, TLS certificates, DNS,

WHOIS/RDAP, logs, forensic artifacts, and data quality.

6. Kill Chain, Diamond Model, and Courses of Action — intrusion mapping, adversary

capabilities, infrastructure, victims, events, and defensive response options.


7. Malware Intelligence — static and behavioral analysis, sandboxing, hashes, strings,

configuration extraction, malware infrastructure, and intelligence pivots.


8. Pivoting and Domain Analysis — relationships among domains, certificates, IPs, registrars,

passive DNS, hosting, subdomains, and linked infrastructure.


9. Intelligence Sharing and Reporting — STIX/TAXII concepts, intelligence products,

assessments, executive reporting, tactical dissemination, and information handling.

,10. Intelligence Application and Threat-Informed Defense — applying intelligence to detection,

hunting, prioritization, risk decisions, incident response, and defensive planning.



Questions


1. While investigating related intrusion activity, Which observation can be especially useful

when investigating whether several domains may share common infrastructure over time?


A. Historical DNS resolution


B. Current keyboard layout


C. Screen brightness


D. File compression ratio


Answer: A

Rationale: Historical DNS information can reveal infrastructure relationships that are no longer

visible from current records.


2. For an analyst working on an active investigation, A vulnerability is actively exploited by an

adversary targeting the organization's technology stack. How can threat intelligence improve

prioritization?


A. Connect exploitation evidence with organizational exposure


B. Treat every vulnerability equally


C. Ignore business context


D. Only examine vendor marketing

,Answer: A

Rationale: Threat intelligence can help prioritize vulnerabilities by connecting adversary activity

to the organization's actual exposure and risk.


3. For an analyst working on an active investigation, Which observation can be especially useful

when investigating whether several domains may share common infrastructure over time?


A. Historical DNS resolution


B. Current keyboard layout


C. Screen brightness


D. File compression ratio


Answer: A

Rationale: Historical DNS information can reveal infrastructure relationships that are no longer

visible from current records.


4. When reviewing collected evidence, Why is source reliability important when analysts

combine information from several intelligence feeds into one assessment?


A. Poor sources can weaken the assessment


B. Reliable sources eliminate uncertainty


C. Source reliability proves attribution


D. Source reliability replaces analysis


Answer: A

, Rationale: Source reliability affects how much confidence analysts should place in collected

information.


5. For an analyst working on an active investigation, A vulnerability is actively exploited by an

adversary targeting the organization's technology stack. How can threat intelligence improve

prioritization?


A. Connect exploitation evidence with organizational exposure


B. Treat every vulnerability equally


C. Ignore business context


D. Only examine vendor marketing


Answer: A

Rationale: Threat intelligence can help prioritize vulnerabilities by connecting adversary activity

to the organization's actual exposure and risk.


6. During a threat intelligence investigation, A malware sample is executed in a controlled

environment to observe files, processes, network connections, and registry changes. What

technique is being used?


A. Behavioral analysis


B. Password cracking


C. Certificate transparency


D. Social engineering

Document information

Uploaded on
August 22, 2026
Number of pages
127
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$34.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAGRADES
4.8
(1066)
Sold
6652
Followers
467
Items
9116
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions