GIAC GCTI Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Cyber Threat Intelligence (GCTI) Exam |
| Exam Number: | GCTI |
| Exam Duration: | 180 minutes |
| Related Certifications: | GIAC Security Essentials (GSEC) GIAC Certified Forensic Analyst (GCFA) GIAC Certified Incident Handler (GCIH) |
| Real Exam Qty: | 82 |
| Passing Score: | 71% |
| Available Languages: | English |
| Exam Format: | CyberLive Practical Exercises, Multiple Choice |
| Exam Price: | $999 USD |
| Certificate Validity Period: | 4 years |
| Recommended Training: | SANS FOR578: Cyber Threat Intelligence |
| Exam Registration: | Pearson VUE Testing Centers GIAC Official Registration |
| Sample Questions: | GIAC GCTI Sample Questions |
| Exam Way: | Web-based, proctored; remote via ProctorU or onsite at Pearson VUE centers; open-book (hardcopy materials allowed) |
| Pre Condition: | No formal prerequisites; recommended experience in cybersecurity, analysis, incident response or threat intelligence roles |
| Official Syllabus URL: | https://www.giac.org/certifications/cyber-threat-intelligence-gcti/ |
GIAC GCTI Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Analytic Frameworks and Models | 20% | - Diamond Model of Intrusion Analysis - Analysis of Competing Hypotheses (ACH) - Courses of Action Matrix - MITRE ATT&CK Framework - Cyber Kill Chain |
| Topic 2: Intelligence Application and Reporting | 15% | - Actionable intelligence production - Audience-specific reporting - Threat hunting and incident response support - Integrating intelligence into security operations |
| Topic 3: Advanced Topics and Tradecraft | 15% | - Counter-intelligence concepts - Threat actor profiling and behavior analysis - Legal, ethical, and privacy considerations |
| Topic 4: Intelligence Analysis Techniques | 20% | - Pattern recognition and anomaly detection - Attribution methodologies and limitations - Malware analysis and intelligence extraction - Link analysis and pivoting - Campaign identification and tracking - Cognitive biases and analytical tradecraft |
| Topic 5: Intelligence Fundamentals | 15% | - Core definitions and concepts - Data sources and collection technologies - Intelligence types: strategic, operational, tactical - Intelligence lifecycle |
| Topic 6: Data Collection and Management | 15% | - Threat feeds and third-party data - Data storage, normalization, and sharing - Technical data sources: logs, network traffic, artifacts - Open Source Intelligence (OSINT) |
GIAC Cyber Threat Intelligence Sample Questions:
Which two data points are commonly used in pivot analysis?
Response:
- A. IP addresses
- B. Wi-Fi passwords
- C. DNS records
- D. Internal employee schedules
Correct Answer: A,C 🗳️
Which of the following best describes "Indicators of Compromise" (IOCs)?
Response:
- A. Procedures for installing antivirus software
- B. Methods to improve network performance
- C. Techniques to encrypt sensitive data
- D. Artifacts observed on a network or in an operating system that indicate a potential intrusion
Correct Answer: D 🗳️
What is the primary purpose of the Courses of Action Matrix in cyber threat intelligence?
Response:
- A. To manage encryption keys
- B. To store threat intelligence data
- C. To enhance network performance
- D. To prioritize responses to identified threats
Correct Answer: D 🗳️
How can cyber intelligence professionals apply lessons learned from previous cyber attacks?
Response:
- A. By improving physical security measures
- B. By educating employees on cybersecurity best practices
- C. By updating incident response protocols
- D. By developing better encryption methods
- E. By enhancing threat modeling techniques
Correct Answer: B,C,E 🗳️
Which tool is commonly used by forensic analysts to investigate digital evidence?
Response:
- A. Forensic imaging tools
- B. Network switches
- C. Wi-Fi analyzers
- D. Password crackers
Correct Answer: A 🗳️
We're so confident of our products that we provide no hassle product exchange.


By Poppy

