
GIAC Information Security Fundamentals
Domain 1Objective 2
Managing and Mitigating Cyber Risk GISF Practice Questions (Page 9)
Part of the Foundations and Risk Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 41–45
- 41
A manufacturing company's security team is designing controls for its industrial control system (ICS) network. The team wants to detect an intruder who has already bypassed the perimeter firewall and is moving laterally inside the network. Which control is most effective for this purpose?
Select an answer first - 42
Which sequence correctly represents the typical order of steps in a cyber risk assessment?
Select an answer first - 43
A company has a mature risk management program with quarterly risk reviews. After a major merger, they integrate a new subsidiary's IT systems. The subsidiary has a different risk assessment methodology and a higher risk appetite. The merged company must maintain compliance with industry regulations. What is the most effective way to update the risk management process?
Select an answer first - 44
A company has deployed a new web application. The security team wants to detect and respond to SQL injection attempts. Which control combination should they implement?
Select an answer first - 45
A multinational company processes personal data of EU citizens and is subject to GDPR. They are evaluating a new data storage provider that offers lower costs but stores data in a country without an adequacy decision. What should the company do to manage the compliance risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.