
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 10)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 46–50
- 46
A university is conducting a risk assessment for its research data. They have identified that the data is highly sensitive and that a breach would cause significant reputational damage. The likelihood of a breach is low because of strong existing controls. What is the appropriate risk treatment?
Select an answer first - 47
A logistics company is evaluating how to handle the risk of a ransomware attack on its shipment tracking system. The system is critical, and the company has a moderate risk appetite. The cost of a full security upgrade is high, but the company has cyber insurance that covers ransomware incidents. Which combination of strategies best balances cost and risk?
Select an answer first - 48
A global company is subject to both GDPR and the California Consumer Privacy Act (CCPA). The company has a risk management program that includes annual risk assessments and continuous monitoring. A new regulation is proposed that would require additional data protection measures. The company's legal team advises that the regulation is likely to pass within the next year. The security team must decide how to respond. Which approach best aligns with the principles of risk monitoring and review?
Select an answer first - 49
A large e-commerce company is conducting a risk assessment for its payment processing system. The system handles millions of transactions daily. The risk assessment team has identified a critical vulnerability in the system's authentication module. The team must decide whether to implement a temporary workaround or shut down the system for a full patch. The system is essential for revenue, and downtime is costly. The vulnerability is actively being exploited in the wild. Which decision best balances risk and business continuity?
Select an answer first - 50
A regional bank is conducting its annual cyber risk assessment. During asset identification, the team lists customer databases, payment processing systems, and employee workstations. The threat modeling step identifies both external attackers and disgruntled insiders. The vulnerability scan reveals an unpatched critical flaw in the customer database server. The bank's risk appetite is low, and the database is essential for daily operations. Which risk treatment approach best aligns with the bank's risk appetite and operational needs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GISF
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.