Question 1
A threat feed providing 10,000 malicious IP addresses per day without context, confidence scores, or analytical commentary is BEST described as providing:
Show answer & explanation
Correct answer: A - Data or information, not intelligence
10 free, exam-style GIAC Cyber Threat Intelligence (GCTI) practice questions with answers and explanations. No signup required. Work through them below, then take the full free GCTI practice test to study every exam domain.
A threat feed providing 10,000 malicious IP addresses per day without context, confidence scores, or analytical commentary is BEST described as providing:
Correct answer: A - Data or information, not intelligence
An analyst receives an alert about a suspicious email with a malicious attachment. Using the integrated framework approach (Kill Chain + Diamond Model + COA Matrix), they should:
Correct answer: C - Map to Delivery phase and identify Diamond Model elements
An ACH matrix shows that Evidence Item 3 is marked 'Consistent' with all five hypotheses. What is the diagnostic value of this evidence?
Correct answer: B - No diagnostic value - it doesn't differentiate between hypotheses
An analyst believes an intrusion was conducted by APT28. When reviewing evidence, the analyst highlights every indicator consistent with APT28 while dismissing evidence pointing to other groups as 'likely coincidental.' This is an example of:
Correct answer: D - Confirmation bias
The Olympic Destroyer malware (targeting the 2018 Winter Olympics) contained code fragments and artifacts deliberately designed to resemble malware from multiple different threat groups. This is an example of:
Correct answer: A - A false flag operation to confuse attribution
An analyst attributes an intrusion based solely on the use of X-Agent malware (historically associated with APT28). The PRIMARY weakness of this attribution is:
Correct answer: D - Single-indicator attribution is unreliable
An analyst examining a memory image wants to identify potential code injection in running processes. The MOST appropriate Volatility plugin is:
Correct answer: C - malfind
An analyst runs the Volatility 'cmdline' plugin on a memory image and sees: powershell.exe -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBj... - The '-enc' flag with a long Base64 string indicates:
Correct answer: B - An encoded PowerShell command used to obfuscate malicious commands
A pivot chain reveals that three adversary domains share the same hosting provider. This hosting provider serves millions of customers. The analyst should:
Correct answer: A - Recognize that the shared hosting provider is NOT diagnostically significant alone
A YARA rule with the condition: uint16(0) == 0x5A4D and ($string1 or $hex1) and filesize < 1MB - will match files that:
Correct answer: D - Are PE files under 1MB with patterns
Practice hundreds more GCTI questions with instant scoring, weak-area drills, and full exam simulations.