GIAC Cyber Threat Intelligence (GCTI)
Examination Questions And Correct
Answers (Verified Answers) Plus
Explanation 2026 Q&A | Instant
Download Pdf
1. What is the primary goal of Cyber Threat Intelligence (CTI)?
A) Block all cyber attacks in real time
B) Replace security operations centers
C) Provide context-driven understanding of adversaries and
threats
D) Encrypt organizational data
Correct Answer: C
,Page 2 of 146
Rationale: CTI focuses on analyzing adversaries, their tactics,
techniques, and motivations to support decision-making—not
direct blocking or encryption. It provides context that enables
proactive defense .
Q2. Which framework is most commonly used to describe
adversary behavior in CTI?
A) ISO 27001
B) MITRE ATT&CK
C) NIST SP 800-53
D) OWASP Top 10
Correct Answer: B
Rationale: MITRE ATT&CK maps real-world adversary tactics,
techniques, and procedures (TTPs) across the full attack lifecycle,
making it the industry standard for describing and categorizing
adversary behavior .
,Page 3 of 146
Q3. What does "TTP" stand for in threat intelligence?
A) Tools, Techniques, Protocols
B) Tactics, Techniques, Procedures
C) Threats, Targets, Payloads
D) Timing, Tracking, Profiling
Correct Answer: B
Rationale: TTPs describe how adversaries operate—their high-
level strategic goals (Tactics), specific methods (Techniques), and
detailed implementations (Procedures) .
Q4. Which CTI type is focused on executive decision-making
and long-term trends?
A) Tactical intelligence
B) Operational intelligence
C) Strategic intelligence
, Page 4 of 146
D) Technical intelligence
Correct Answer: C
Rationale: Strategic CTI supports executive-level risk and
business decisions by focusing on long-term trends, threat
landscapes, and potential business impacts. It answers "What is
likely to happen to our industry?" .
Q5. What is an Indicator of Compromise (IOC)?
A) Business risk statement
B) Evidence of potential intrusion or malicious activity
C) Firewall configuration rule
D) Encryption method
Correct Answer: B
Rationale: IOCs are forensic artifacts (IP addresses, file hashes,
domain names, registry keys) that indicate potential malicious
activity on a system or network .