Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Fundamentals

Domain 1Objective 1

Foundations of Cybersecurity GISF Practice Questions (Page 4)

Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
5concepts

Questions 16–20

  1. 16application · medium

    A small business wants to improve its security posture but has limited budget and no dedicated security staff. They need a practical starting point that is widely recognized and provides a prioritized set of actions. Which approach should they adopt?

    Select an answer first
  2. 17expert · hard

    A company is conducting a risk assessment for its customer database. They identify that a successful ransomware attack could encrypt the database and cause significant downtime. The company decides to implement daily backups and test restoration procedures. In risk management terms, what is the company doing?

    Select an answer first
  3. 18application · medium

    A hospital is planning to implement a new electronic health record (EHR) system. The risk management team is conducting a risk assessment. They identify that a power outage could make the EHR unavailable for several hours, impacting patient care. They decide to install an uninterruptible power supply (UPS) and a backup generator. In risk management terms, what is the UPS and generator considered?

    Select an answer first
  4. 19expert · hard

    A hospital is evaluating its risk management approach for a new patient portal. The portal will store sensitive health data. The hospital must balance patient safety (availability) with strict privacy regulations (confidentiality). The security team proposes implementing multi-factor authentication (MFA) for all users, encrypting all data, and deploying redundant servers. However, the clinical staff complain that MFA slows down access during emergencies. Which approach best balances the competing requirements?

    Select an answer first
  5. 20foundation · easy

    An employee with legitimate access to company systems intentionally exfiltrates sensitive customer data to a competitor. Which type of threat does this represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.