
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 2)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 6–10
- 6
A financial services firm is required by regulators to maintain a certain level of cybersecurity insurance. They have identified a risk that is too costly to mitigate fully. Which strategy should they use to address the residual risk?
Select an answer first - 7
A startup is developing a mobile app that collects user location data. The founders want to minimize cyber risk but have limited resources. They are deciding which risks to address first. The risk assessment shows that a data breach could result in regulatory fines and loss of user trust, while a temporary app outage would cause minor inconvenience. Which approach best aligns with the startup's limited resources?
Select an answer first - 8
A bank is designing a new online banking platform. They must balance customer convenience with security. They are considering implementing multi-factor authentication (MFA) for all users. The marketing team is concerned that MFA will reduce user adoption. The compliance team notes that regulators require strong authentication for financial transactions. What is the best approach?
Select an answer first - 9
A company has implemented a risk management program and is now in the monitoring phase. They have deployed new IoT devices and a new cloud-based CRM system. Select all that apply: Which actions should they take to ensure the risk management process remains effective?
Select an answer first - 10
A university's IT department is performing a risk assessment for its student records system. They have identified that the system contains sensitive personal data, the primary threat is a ransomware attack, and the system has a known vulnerability in its web interface. The team calculates the likelihood as high and the impact as high. According to standard risk calculation, what is the next step in the risk assessment process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.