
GIAC Information Security Fundamentals
Domain 1Objective 1
Foundations of Cybersecurity GISF Practice Questions (Page 7)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 31–35
- 31
Which security best practice involves granting users only the permissions necessary to perform their job functions?
Select an answer first - 32
A company has experienced a series of phishing attacks that bypassed its email filter. The security team is considering two options: (1) increase the spam filter sensitivity, which may block legitimate emails, or (2) implement mandatory security awareness training for all employees. Which approach is the most effective long-term strategy?
Select an answer first - 33
Which category of security control is designed to stop an incident from occurring in the first place?
Select an answer first - 34
Which type of cyber threat involves an attacker sending fraudulent emails that appear to come from a trusted source to trick recipients into revealing sensitive information?
Select an answer first - 35
An organization deploys an intrusion detection system (IDS) to monitor network traffic for suspicious activity. Which category of security control does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.