
GIAC Information Security Fundamentals
Domain 4Objective 1
Foundations of Cryptography and Digital Trust GISF Practice Questions (Page 9)
Part of the Cryptography and Identity domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 41–45
- 41
A developer wants to verify that a downloaded file matches the original published by the vendor. The vendor provides a hash value on their website. What should the developer do?
Select an answer first - 42
A software vendor distributes a signed update file. The vendor publishes the hash of the file on its website. A user downloads the file and the hash, but the user does not have the vendor's public key. What can the user verify with the published hash?
Select an answer first - 43
A software vendor signs its releases with a code-signing certificate. A user downloads a signed executable and verifies the signature. What can the user conclude?
Select an answer first - 44
A security team is reviewing a recent incident where an attacker intercepted communications between a client and a server. The attacker was able to read and modify the traffic without either party detecting the interception. Which cryptographic control would have MOST effectively prevented this attack?
Select an answer first - 45
During certificate validation, what does a client check to ensure a certificate has not been revoked before its expiration date?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GISF
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.