
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 1)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 1–5
- 1
A small e-commerce company sells handmade crafts online. A risk assessment identifies that a distributed denial-of-service (DDoS) attack could take down the website for hours, causing significant revenue loss. The company has a limited IT budget and no dedicated security staff. Which risk mitigation strategy is most appropriate for this scenario?
Select an answer first - 2
A government agency is required by law to protect classified information. The agency is considering using a public cloud service for some of its non-classified administrative data. The risk assessment shows that the public cloud provider has strong security controls, but the agency is concerned about the legal requirement that data be stored within the country. The provider offers a region within the country. The agency's risk appetite is low. Which risk treatment approach is most appropriate?
Select an answer first - 3
A regional bank is conducting its annual cyber risk assessment. The assessment team has identified customer transaction data as a critical asset, a threat actor profile of organized crime groups, and a known vulnerability in the online banking platform. They are now calculating the risk for this scenario. Which combination of factors should the team use to calculate the risk score?
Select an answer first - 4
A company is evaluating how to handle a high-risk vulnerability in a customer-facing application. The vulnerability could lead to a data breach, and the company is subject to data protection regulations. Select all that apply: Which risk mitigation strategies are appropriate to consider?
Select an answer first - 5
A retail company's security team is reviewing its incident response capabilities. After a recent malware infection, they realized that the antivirus software detected the malware only after it had encrypted several files. The team wants to add a control that detects malware earlier in the infection chain. Which control would best achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.