GIAC GOSI Exam Overview:
| Certification Vendor: | GIAC (SANS Institute) |
|---|---|
| Exam Name: | GIAC Open Source Intelligence (GOSI) Certification Exam |
| Exam Number: | GOSI |
| Exam Duration: | 120-180 |
| Passing Score: | 73% |
| Related Certifications: | GIAC Cyber Threat Intelligence (GCTI) |
| Exam Format: | Proctored Online or Testing Center, Multiple Choice |
| Available Languages: | English |
| Certificate Validity Period: | 4 years |
| Exam Price: | $979 USD (standard GIAC exam attempt, subject to change) |
| Real Exam Qty: | Approximately 106 |
| Recommended Training: | SANS SEC487: Open-Source Intelligence (OSINT) Gathering and Analysis Techniques |
| Exam Registration: | SANS Institute Training & Registration GIAC Official Certification Page |
| Sample Questions: | GIAC GOSI Sample Questions |
| Exam Way: | Computer-based proctored exam (online or testing center) |
| Pre Condition: | No formal prerequisites required; foundational cybersecurity or intelligence analysis knowledge recommended. |
| Official Syllabus URL: | https://www.giac.org/certifications/open-source-intelligence-gosi/ |
GIAC GOSI Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Reporting and Intelligence Delivery | - Structuring intelligence reports - Communicating findings effectively |
| Tools and Technical OSINT | - Dark web and deep web reconnaissance - OSINT automation tools - Metadata extraction and analysis |
| Legal, Ethics, and Compliance | - Ethical intelligence gathering practices - Legal boundaries of OSINT collection |
| Information Collection Techniques | - Social media intelligence collection - Advanced search engine techniques - Data harvesting from public sources |
| OSINT Fundamentals | - Principles of open-source intelligence - OSINT lifecycle and methodology |
| Analysis and Correlation | - Link analysis and entity mapping - Pattern identification in datasets |
GIAC Open Source Intelligence Certification GOSI Sample Questions:
What role do API integrations play in OSINT research?
- A. They provide unauthorized access to databases
- B. They allow structured data collection from various sources
- C. They modify metadata in social media images
- D. They decrypt files with unknown passwords
Correct Answer: B 🗳️
What is the primary objective of conducting OSINT investigations on a business?
- A. To assess publicly available data for potential risks and threats
- B. To exploit business vulnerabilities for competitive advantage
- C. To manipulate financial markets using confidential business data
- D. To gather intelligence on competitors for business espionage
Correct Answer: A 🗳️
What security precautions should an OSINT analyst take when using search engines? (Choose two)
- A. Use social media accounts with real personal information
- B. Disable all security features to avoid detection
- C. Regularly clear cookies and browsing history
- D. Use private search engines like DuckDuckGo
Correct Answer: C,D 🗳️
When performing OSINT on an individual, what online sources are commonly used to verify employment history? (Choose two)
- A. Breach databases
- B. WHOIS records
- C. LinkedIn
- D. Court filings
Correct Answer: C,D 🗳️
Which file formats typically contain embedded metadata useful for OSINT? (Choose two)
- A. CSV
- B. JPEG
- C. PDF
- D. TXT
Correct Answer: B,C 🗳️
We're so confident of our products that we provide no hassle product exchange.


By Angela

