
GIAC Information Security Fundamentals
Domain 3Objective 4
Defensive Technologies and Emerging Intelligence GISF Practice Questions (Page 7)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 31–35
- 31
An organization's endpoints are infected with ransomware that encrypts files and spreads through network shares. The EPP has detected the ransomware but cannot stop it from spreading. The organization wants to contain the infection and prevent further spread. Which action should be taken first?
Select an answer first - 32
What does the principle of least privilege state?
Select an answer first - 33
What is the primary purpose of vulnerability scanning?
Select an answer first - 34
A company must protect sensitive data in a database that is accessed by multiple applications. Some applications need to query the data, while others only need to store it. The company wants to ensure that even if the database server is compromised, the data remains unreadable. Which approach best meets this requirement?
Select an answer first - 35
A security team subscribes to a threat intelligence feed that provides indicators of compromise (IOCs) for a new ransomware campaign. The team wants to use this intelligence to proactively defend their environment. Which action best applies this threat intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.