
GIAC Information Security Fundamentals
Domain 4Objective 2
Identity, Access and Data Protection GISF Practice Questions (Page 1)
Part of the Cryptography and Identity domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 1–5
- 1
A security engineer needs to protect data in transit between a web browser and a web server. Which technique should be used?
Select an answer first - 2
Which privacy principle requires that organizations collect only the personal data necessary for a specified purpose?
Select an answer first - 3
Which regulatory framework grants individuals the right to request deletion of their personal data?
Select an answer first - 4
Which access control mechanism is a list of permissions attached to an object that specifies which subjects can access it and how?
Select an answer first - 5
A company is designing a data protection policy. They have a dataset containing customer names and email addresses, and another dataset containing salary information. They need to apply different levels of protection based on the sensitivity of the data. What should they do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.