
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 8)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 36–40
- 36
A utility company operates both corporate IT and industrial control systems (ICS) for power generation. The security team is designing a monitoring solution. They have a limited number of security analysts and need to detect both external attacks and insider threats. The ICS network has legacy equipment that cannot support modern security agents. The corporate network has modern endpoints that can support agents. Which approach best balances detection coverage and resource constraints?
Select an answer first - 37
Which statement best defines cyber risk in the context of organizational risk management?
Select an answer first - 38
A global company is subject to both GDPR and the U.S. Health Insurance Portability and Accountability Act (HIPAA). They are evaluating a cloud storage provider that offers data centers in the EU and the U.S. The company wants to minimize compliance risk while maintaining performance. What should they do?
Select an answer first - 39
A company processes credit card payments and must comply with the Payment Card Industry Data Security Standard (PCI DSS). How does this contractual/regulatory requirement affect its risk mitigation approach?
Select an answer first - 40
What is the primary purpose of periodically reviewing and updating the organization's risk management process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.