
GIAC Information Security Fundamentals
Domain 4Objective 2
Identity, Access and Data Protection GISF Practice Questions (Page 2)
Part of the Cryptography and Identity domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 6–10
- 6
A hospital needs to control access to electronic health records. The compliance team requires that access be granted based on the user's role (e.g., doctor, nurse) and the patient's consent status. The system must also support emergency override by a senior clinician. Which access control model best supports these requirements?
Select an answer first - 7
A company needs to protect sensitive data in a database so that even database administrators cannot view the actual values, but the application must be able to retrieve the original values for processing. Which technique should be used?
Select an answer first - 8
A company is implementing SSO across multiple applications. They want to ensure that when an employee leaves, their access is revoked across all applications immediately. Which approach best achieves this?
Select an answer first - 9
An employee is leaving the company. The IT team needs to ensure that the employee's access to all systems is removed promptly. Which process is most directly responsible for this?
Select an answer first - 10
In which access control model does the data owner decide who can access a resource?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.