
GIAC Information Security Fundamentals
Domain 3Objective 4
Defensive Technologies and Emerging Intelligence GISF Practice Questions (Page 6)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 26–30
- 26
Which of the following is a capability that an endpoint protection platform (EPP) typically provides beyond traditional antivirus?
Select an answer first - 27
A company's software development team uses a third-party component that was recently found to contain malicious code inserted by the component's maintainer. The company's application is already in production. Which defensive measure is most effective in mitigating the impact of this supply chain attack?
Select an answer first - 28
A company wants to design a layered defense for its new web application. The application will be accessible from the internet and will store sensitive customer data. Which set of controls best implements defense-in-depth?
Select an answer first - 29
A company is designing a defense-in-depth strategy for a new application that handles sensitive customer data. The application will be accessible from the internet. Which set of controls best represents a layered defense?
Select an answer first - 30
What is the primary purpose of encrypting data at rest?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.