
GIAC Information Security Fundamentals
Domain 4Objective 2
Identity, Access and Data Protection GISF Practice Questions (Page 5)
Part of the Cryptography and Identity domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 21–25
- 21
Which authentication method uses a cryptographic key pair to verify a user's identity?
Select an answer first - 22
A bank wants to implement multi-factor authentication for online banking. They already require a password. Which additional factor would be considered a possession factor?
Select an answer first - 23
A company is implementing a new authentication system and wants to use a method that is resistant to phishing and does not require users to remember complex passwords. Which authentication method best meets these requirements?
Select an answer first - 24
Which IAM concept allows a user to authenticate once and then access multiple applications without re-entering credentials?
Select an answer first - 25
Which data protection technique replaces sensitive data with a non-sensitive placeholder that can be mapped back to the original value in a secure vault?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.