
GIAC Information Security Fundamentals
Domain 4Objective 1
Foundations of Cryptography and Digital Trust GISF Practice Questions (Page 3)
Part of the Cryptography and Identity domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 11–15
- 11
Your company's web application uses a certificate issued by an internal CA. A new employee reports that the browser shows a certificate error. The certificate is not expired and the domain name matches. What is the most likely cause?
Select an answer first - 12
A user receives a certificate warning in the browser when visiting an internal website. The certificate is issued by the company's internal CA, but the browser does not trust it. What is the most likely cause?
Select an answer first - 13
How does a digital signature provide non-repudiation?
Select an answer first - 14
A company uses symmetric encryption to protect data at rest. The security team wants to reduce the risk of a single key compromise exposing all data. Which practice is most effective?
Select an answer first - 15
A company needs to encrypt large volumes of data stored on a file server. The data is accessed by multiple authorized users. The security team wants to minimize the performance impact of encryption and simplify key management. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.