
GIAC Information Security Fundamentals
The GIAC Information Security Fundamentals (GISF) certification validates a practitioner's expertise in the foundations of security, computer functions and networking, introductory cryptography, and cybersecurity technologies. It is designed for anyone new to cybersecurity, non-IT security managers, and career-changers who need a solid introduction to security fundamentals. Earning GISF demonstrates that you understand key information security concepts and can apply best practices to protect organizations against threats and risks.
577 practice questions · Updated 2026-07-30
GISF Curriculum
Every domain, objective, and concept the GISF exam measures.
- Cybersecurity Fundamentals
- Threat Landscape
- Risk Management Basics
- Security Controls
- Security Frameworks and Best Practices
- Cyber Risk Management Fundamentals
- Risk Assessment Process
- Risk Mitigation Strategies
- Security Controls
- Risk Monitoring and Review
- Compliance and Regulatory Considerations
- Security Foundations
- Risk Management Fundamentals
- Security Awareness
- Security Policies and Procedures
- Security Roles and Responsibilities
- OSI Model Layers
- TCP/IP Model
- Encapsulation and De-encapsulation
- IP Addressing and Subnetting
- MAC Addressing and ARP
- TCP and UDP Protocols
- Ports and Sockets
- DNS and Name Resolution
- DHCP and IP Configuration
- Routing and Switching Basics
- Network Topologies and Devices
- Network Security Fundamentals
- Network Architecture Models
- Secure Network Design
- Network Devices and Security
- Network Protocols and Security
- Network Access Control
- Wireless Network Security
- Network Monitoring and Analysis
- Network Threats and Mitigations
- Network Security Policies and Procedures
- Securing Connected Environments
- Cloud Security Fundamentals
- Cloud Deployment and Service Models
- Identity and Access Management in the Cloud
- Data Protection in the Cloud
- Cloud Network Security
- Compliance and Governance in the Cloud
- Incident Response in Cloud Environments
- Adversary profiling
- Threat actor types
- Threat modeling methodologies
- Attack vectors and surfaces
- Indicators of compromise (IoCs)
- Tactics, techniques, and procedures (TTPs)
- Threat intelligence lifecycle
- Frameworks for adversary analysis
- Attribution challenges
- Defensive countermeasures
- Intrusion Lifecycle
- Initial Access Vectors
- Phishing Techniques
- Exploitation of Vulnerabilities
- Credential-Based Access
- Supply Chain Attacks
- Removable Media Attacks
- Social Engineering
- Detection and Prevention
- Post-Exploitation Fundamentals
- Persistence Mechanisms
- Privilege Escalation
- Lateral Movement
- Data Exfiltration
- Advanced Threat Tactics
- Living off the Land
- Command and Control (C2)
- Defensive Countermeasures
- Defensive Technologies Overview
- Firewalls and Network Segmentation
- Intrusion Detection and Prevention Systems
- Endpoint Protection and Antivirus
- Encryption and Data Protection
- Identity and Access Management
- Security Information and Event Management (SIEM)
- Vulnerability Management and Patching
- Emerging Intelligence and Threat Intelligence
- Emerging Threats and Attack Vectors
- Defensive Strategies and Best Practices
- Cryptography Fundamentals
- Symmetric vs. Asymmetric Encryption
- Hash Functions and Digital Signatures
- Public Key Infrastructure (PKI)
- Digital Certificates and Trust
- Key Management
- Cryptographic Attacks and Weaknesses
- Identity Fundamentals
- Authentication Methods
- Access Control Models
- Access Control Mechanisms
- Identity and Access Management (IAM)
- Data Classification
- Data Protection Techniques
- Data Privacy and Compliance
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GISF, so none is invented.