
GIAC Information Security Fundamentals
Domain 4Objective 2
Identity, Access and Data Protection GISF Practice Questions (Page 3)
Part of the Cryptography and Identity domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 11–15
- 11
A system administrator needs to grant a specific user read-only access to a file while denying all other users. The file system supports both ACLs and group policies. Which mechanism is the most direct and appropriate for this requirement?
Select an answer first - 12
A system administrator wants to enforce a company policy that only members of the 'Finance' group can access the payroll folder. Which mechanism should they use?
Select an answer first - 13
Which access control mechanism grants access based on a token or key held by the subject rather than a list on the object?
Select an answer first - 14
Which data protection technique converts data into a fixed-length string that cannot be reversed to recover the original data?
Select an answer first - 15
A multinational company processes personal data of EU citizens. They want to ensure compliance with GDPR. Which practice is most directly aligned with GDPR requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.