
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 3)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 11–15
- 11
A software development company stores source code in a cloud repository. A new contract with a client requires that all source code be encrypted at rest and that access be logged. The company's current cloud provider offers encryption by default and access logging. What is the company's primary obligation under this contractual requirement?
Select an answer first - 12
A hospital is evaluating the risk of ransomware attacks on its patient records. The IT director proposes purchasing cyber insurance to cover potential ransom payments and business interruption costs. The compliance officer notes that insurance does not reduce the likelihood of an attack and that HIPAA requires safeguards to protect ePHI. The hospital has a limited budget. Which approach best balances risk transfer and compliance?
Select an answer first - 13
A manufacturing company relies on a legacy system that is critical to production. The system has known vulnerabilities that cannot be patched because the vendor no longer supports it. The company has a low risk tolerance and cannot afford to replace the system this year. Which combination of strategies best manages the risk?
Select an answer first - 14
A company has implemented a risk management program and conducted an initial risk assessment. Six months later, they have deployed new cloud services and changed their business processes. What should the risk management team do to ensure the program remains effective?
Select an answer first - 15
A healthcare organization has implemented a risk management program and is required by regulation to review its risk posture regularly. The security team has set up automated vulnerability scanning and weekly review meetings. However, the team notices that new critical vulnerabilities are being disclosed daily, and some are not covered by the current scanning tools. What should the team do to improve its risk monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.