Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Fundamentals

Domain 3Objective 2

Intrusion and Initial Access Techniques GISF Practice Questions (Page 2)

Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
9concepts

Questions 6–10

  1. 6application · medium

    An organization discovers that an attacker accessed their cloud email system using a valid account. The account belonged to a former employee whose credentials were never disabled. Which initial access vector is most directly demonstrated?

    Select an answer first
  2. 7foundation · easy

    What is the primary difference between phishing and spear-phishing?

    Select an answer first
  3. 8foundation · easy

    What is a basic detection measure for credential-based initial access attacks?

    Select an answer first
  4. 9expert · hard

    A company has a mature security awareness program, but a spear-phishing campaign successfully compromised a senior executive. The email was highly personalized, referencing a recent conference the executive attended, and came from a compromised account of a known business partner. Which additional control would be most effective in preventing this type of attack?

    Select an answer first
  5. 10foundation · easy

    Why are supply chain attacks particularly dangerous for gaining initial access?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.