Free GOSI sample questions
Real questions from the GIAC Open Source Intelligence practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 8 of 17 free sample questions.
During an investigation, an analyst discovers a target's personal blog. To maintain operational security (OPSEC) and prevent the target from identifying the investigator's real IP address, the analyst uses a VPN. However, the analyst is concerned about WebRTC leaks exposing their true IP. Which of the following actions is the MOST effective way to mitigate WebRTC leaks while browsing?
Which Google search operator would an analyst use to find Excel spreadsheets containing the word 'budget' located specifically on government websites ending in .gov?
An OSINT investigator is analyzing a target's presence on a specific social media platform. The investigator needs to determine the exact date and time a user account was created to correlate it with known events. The platform does not display this information on the profile page. Which technique would most reliably provide this data without interacting with the target?
You are investigating a shell company suspected of money laundering. You have identified a website purportedly belonging to the company. Which of the following records would be MOST valuable for identifying the underlying infrastructure provider and potentially the real geographic location of the server, even if the domain uses a privacy protection service?
Select TWO primary reasons why an OSINT investigator would use a 'sock puppet' account during a social media investigation. (Select TWO)
A multinational corporation has suffered a data breach. An OSINT analyst is tasked with determining if any executive credentials have been exposed on the dark web. The analyst decides to use an automated tool to search multiple paste sites and marketplaces. Which of the following is the MOST critical technical constraint the analyst must configure to avoid being blocked by these services?
True or False: When conducting a 'passive' OSINT investigation on a target organization's network infrastructure, sending packets directly to the target's firewall to banner grab is considered an acceptable passive technique.
9 more free samples are waiting
Create a free account to unlock the whole GOSI sample bank, or get full access to all 250 practice questions in the simulator.