
GIAC Information Security Fundamentals
Domain 3Objective 2
Intrusion and Initial Access Techniques GISF Practice Questions (Page 3)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 11–15
- 11
An organization wants to prevent malware infections from USB drives, but some employees legitimately need to use USB drives for work. Which control balances security and usability?
Select an answer first - 12
What is a common technique used in removable media attacks to trick users into inserting a malicious USB drive?
Select an answer first - 13
How do attackers commonly use stolen credentials to gain initial access to a network?
Select an answer first - 14
An attacker exploits a known vulnerability in an internet-facing web server to gain a foothold. Which initial access vector does this represent?
Select an answer first - 15
An organization has a strong email security gateway that blocks most phishing emails. However, an attacker successfully gains access by calling the help desk and convincing a technician to reset a password. The attacker then uses the new password to log in. Which combination of techniques did the attacker use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.