Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Information Security Fundamentals

GISFGIAC Information Security Fundamentals (GISF)

The GIAC Information Security Fundamentals (GISF) certification validates a practitioner's expertise in the foundations of security, computer functions and networking, introductory cryptography, and cybersecurity technologies. It is designed for anyone new to cybersecurity, non-IT security managers, and career-changers who need a solid introduction to security fundamentals. Earning GISF demonstrates that you understand key information security concepts and can apply best practices to protect organizations against threats and risks.

577 practice questions · Updated 2026-07-30

4Domains
12Objectives
99Concepts
577Questions

GISF Curriculum

Every domain, objective, and concept the GISF exam measures.

Foundations of Cybersecurity

5 concepts · 40 questions
  1. Cybersecurity Fundamentals
  2. Threat Landscape
  3. Risk Management Basics
  4. Security Controls
  5. Security Frameworks and Best Practices

Managing and Mitigating Cyber Risk

6 concepts · 50 questions
  1. Cyber Risk Management Fundamentals
  2. Risk Assessment Process
  3. Risk Mitigation Strategies
  4. Security Controls
  5. Risk Monitoring and Review
  6. Compliance and Regulatory Considerations

Security Foundations and Awareness

5 concepts · 38 questions
  1. Security Foundations
  2. Risk Management Fundamentals
  3. Security Awareness
  4. Security Policies and Procedures
  5. Security Roles and Responsibilities

Foundations of Network Communication

11 concepts · 53 questions
  1. OSI Model Layers
  2. TCP/IP Model
  3. Encapsulation and De-encapsulation
  4. IP Addressing and Subnetting
  5. MAC Addressing and ARP
  6. TCP and UDP Protocols
  7. Ports and Sockets
  8. DNS and Name Resolution
  9. DHCP and IP Configuration
  10. Routing and Switching Basics
  11. Network Topologies and Devices

Network Security and Architecture

10 concepts · 52 questions
  1. Network Security Fundamentals
  2. Network Architecture Models
  3. Secure Network Design
  4. Network Devices and Security
  5. Network Protocols and Security
  6. Network Access Control
  7. Wireless Network Security
  8. Network Monitoring and Analysis
  9. Network Threats and Mitigations
  10. Network Security Policies and Procedures
  1. Securing Connected Environments
  2. Cloud Security Fundamentals
  3. Cloud Deployment and Service Models
  4. Identity and Access Management in the Cloud
  5. Data Protection in the Cloud
  6. Cloud Network Security
  7. Compliance and Governance in the Cloud
  8. Incident Response in Cloud Environments

Adversary Analysis and Threat Frameworks

10 concepts · 55 questions
  1. Adversary profiling
  2. Threat actor types
  3. Threat modeling methodologies
  4. Attack vectors and surfaces
  5. Indicators of compromise (IoCs)
  6. Tactics, techniques, and procedures (TTPs)
  7. Threat intelligence lifecycle
  8. Frameworks for adversary analysis
  9. Attribution challenges
  10. Defensive countermeasures

Intrusion and Initial Access Techniques

9 concepts · 45 questions
  1. Intrusion Lifecycle
  2. Initial Access Vectors
  3. Phishing Techniques
  4. Exploitation of Vulnerabilities
  5. Credential-Based Access
  6. Supply Chain Attacks
  7. Removable Media Attacks
  8. Social Engineering
  9. Detection and Prevention
  1. Post-Exploitation Fundamentals
  2. Persistence Mechanisms
  3. Privilege Escalation
  4. Lateral Movement
  5. Data Exfiltration
  6. Advanced Threat Tactics
  7. Living off the Land
  8. Command and Control (C2)
  9. Defensive Countermeasures
  1. Defensive Technologies Overview
  2. Firewalls and Network Segmentation
  3. Intrusion Detection and Prevention Systems
  4. Endpoint Protection and Antivirus
  5. Encryption and Data Protection
  6. Identity and Access Management
  7. Security Information and Event Management (SIEM)
  8. Vulnerability Management and Patching
  9. Emerging Intelligence and Threat Intelligence
  10. Emerging Threats and Attack Vectors
  11. Defensive Strategies and Best Practices

  1. Cryptography Fundamentals
  2. Symmetric vs. Asymmetric Encryption
  3. Hash Functions and Digital Signatures
  4. Public Key Infrastructure (PKI)
  5. Digital Certificates and Trust
  6. Key Management
  7. Cryptographic Attacks and Weaknesses

Identity, Access and Data Protection

8 concepts · 38 questions
  1. Identity Fundamentals
  2. Authentication Methods
  3. Access Control Models
  4. Access Control Mechanisms
  5. Identity and Access Management (IAM)
  6. Data Classification
  7. Data Protection Techniques
  8. Data Privacy and Compliance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GISF, so none is invented.