
GIAC Information Security Fundamentals
Domain 3Objective 2
Intrusion and Initial Access Techniques GISF Practice Questions (Page 4)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 16–20
- 16
A company's security policy prohibits the use of personal USB drives. However, an employee uses one to transfer files and inadvertently introduces malware that spreads to the network. Which control would be most effective in enforcing this policy?
Select an answer first - 17
An attacker sends an email to a specific finance employee, referencing a recent invoice and containing a malicious attachment. The email is personalized with the employee's name and job title. Which technique is this?
Select an answer first - 18
A company wants to reduce the risk of initial access via phishing and credential theft, but they have a limited budget. Which control provides the best cost-effective protection?
Select an answer first - 19
An attacker calls an employee, pretending to be a senior executive, and urgently asks for the employee's login credentials to fix a 'critical issue.' The employee provides them. Which social engineering tactic is this?
Select an answer first - 20
What is the primary goal of social engineering in the context of initial access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.