Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Fundamentals

Domain 3Objective 4

Defensive Technologies and Emerging Intelligence GISF Practice Questions (Page 4)

Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
11concepts

Questions 16–20

  1. 16application · medium

    A security manager wants to categorize the defensive technologies currently deployed. The organization uses a firewall, an IDS, a SIEM, and endpoint antivirus. Which categorization correctly groups these technologies by their primary function?

    Select an answer first
  2. 17expert · hard

    A threat intelligence analyst receives a feed that includes a large number of IOCs, but many are false positives and the feed has a high volume. The analyst wants to use the intelligence to prioritize defenses without overwhelming the SOC. Which approach is most effective?

    Select an answer first
  3. 18application · medium

    A company's mobile workforce uses laptops that contain sensitive customer data. The laptops are occasionally lost or stolen. The company wants to ensure that the data on the laptops is unreadable if the device is stolen, and that only authorized users can access the data. Which control is most effective?

    Select an answer first
  4. 19application · medium

    A company's finance team handles sensitive payroll data. The security policy requires that users authenticate with something they know and something they have, and that they only have access to the specific records needed for their job. Which set of controls implements this policy?

    Select an answer first
  5. 20application · medium

    A security analyst notices repeated SQL injection attempts against a web application. The attempts are blocked by the web application firewall, but the analyst wants to understand the full scope of the attacks, including source IPs, payload variations, and whether any attempts evaded the WAF. Which control is most appropriate to provide this visibility?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.