
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 4)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 16–20
- 16
What is the primary purpose of implementing a cyber risk management program within an organization?
Select an answer first - 17
A healthcare provider handles protected health information (PHI) and is subject to HIPAA. They have identified a high risk of data breach through unencrypted laptops. The cost of implementing full-disk encryption is significant but far less than the potential fines and reputational damage. Which risk mitigation strategy should the provider adopt?
Select an answer first - 18
Which of the following is an example of a corrective security control?
Select an answer first - 19
An organization decides to discontinue a legacy online service that is no longer profitable and poses a high security risk. Which risk mitigation strategy is being applied?
Select an answer first - 20
A software company stores customer data and is subject to the California Consumer Privacy Act (CCPA). They are designing a new data storage solution. Which requirement must they incorporate into their risk management decisions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.