Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Fundamentals

Domain 3Objective 1

Adversary Analysis and Threat Frameworks GISF Practice Questions (Page 7)

Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 31–35

  1. 31application · medium

    A company's security team is reviewing its attack surface after deploying a new web application that allows customers to upload files. The application is hosted on a public cloud server with a public IP address. Which of the following is the most direct attack vector introduced by this deployment?

    Select an answer first
  2. 32expert · hard

    A security team has identified a cyber attack that uses tools and techniques that are publicly attributed to a known advanced persistent threat (APT) group. However, the team also notices that the attack infrastructure includes servers in a country that is not typically associated with that group. What should the team conclude about attribution?

    Select an answer first
  3. 33foundation · easy

    Based on adversary analysis, which defensive countermeasure is most appropriate to mitigate the risk of phishing attacks?

    Select an answer first
  4. 34expert · hard

    An incident responder is analyzing a breach where the attacker gained access via a phishing email, used a legitimate administrative tool for lateral movement, and then encrypted files. The responder wants to use the Cyber Kill Chain to identify where detection could have prevented the attack. Which stage of the Kill Chain should the responder focus on to improve prevention?

    Select an answer first
  5. 35application · medium

    A healthcare organization is conducting a threat model for its new patient portal. The team is concerned about unauthorized access to patient data. They decide to use DREAD to assess the risks of identified threats. What is the primary purpose of using DREAD in this context?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.