
GIAC Information Security Fundamentals
Domain 1Objective 1
Foundations of Cybersecurity GISF Practice Questions (Page 1)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 1–5
- 1
A company is designing a new system that will store sensitive customer data. The system must ensure that data is not altered during transmission and that only authorized users can access it. Which combination of security goals does this requirement represent?
Select an answer first - 2
A university's IT department is configuring a new research database that contains sensitive human subject data. The university's policy requires that the data be protected from unauthorized access and that any breach be detected quickly. Which combination of controls best meets these requirements?
Select an answer first - 3
A regional bank is deploying a new online loan application. The compliance team requires that customer financial data be encrypted in transit and at rest, while the operations team needs the application to remain available during peak hours. The security team is asked to select controls that address these requirements. Which combination of controls best satisfies the stated requirements?
Select an answer first - 4
A company is performing a risk assessment and has identified that a legacy server has a known unpatched vulnerability. The server is not critical to operations, and the cost to replace it is high. The company decides to accept the risk. Which step in the risk management process does this decision represent?
Select an answer first - 5
A mid-sized company is choosing a security framework to guide its program. They have a small security team, limited budget, and need to comply with a customer requirement to demonstrate due care. They are considering ISO/IEC 27001, NIST Cybersecurity Framework (CSF), and PCI DSS (since they accept credit cards). Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.