
GIAC Information Security Fundamentals
Domain 2Objective 3
Securing Connected and Cloud-Based Environments GISF Practice Questions (Page 3)
Part of the Network and Systems Security domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~14–22 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 11–15
- 11
A company stores sensitive files in a cloud storage service. They want to ensure that even the cloud provider cannot access the plaintext data. Which encryption strategy should they use?
Select an answer first - 12
A company processes credit card payments and uses a cloud service to store transaction data. They need to comply with PCI DSS. Which responsibility is most likely the customer's?
Select an answer first - 13
A company's cloud environment is under a distributed denial-of-service (DDoS) attack. The attack is targeting the public IP address of their web application. They want to mitigate the attack while maintaining availability for legitimate users. Which control is most effective?
Select an answer first - 14
A company uses a cloud database to store customer records. They need to protect the data while it is being transmitted between the application and the database. Which control is most appropriate?
Select an answer first - 15
Which cloud network security control is used to filter traffic between subnets within a virtual network?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.