
GIAC Information Security Fundamentals
Domain 2Objective 3
Securing Connected and Cloud-Based Environments GISF Practice Questions (Page 7)
Part of the Network and Systems Security domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~14–22 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 31–35
- 31
A company's cloud environment has a virtual network with multiple subnets. They want to monitor traffic between subnets for suspicious activity. Which control is most effective?
Select an answer first - 32
A security analyst suspects a compromised virtual machine in a cloud environment. They need to preserve evidence for forensic analysis. Which step should they take FIRST?
Select an answer first - 33
A security analyst is reviewing the risks introduced by a building's new network-connected HVAC controllers. Which characteristic of these IoT devices most directly increases their attack surface compared to traditional enterprise servers?
Select an answer first - 34
A company has a cloud environment with multiple application tiers. They want to limit the impact of a compromise in one tier. Which architecture is MOST effective?
Select an answer first - 35
A company experiences a security incident in its cloud environment. The security team needs to collect evidence for forensic analysis. Which action is most appropriate in a cloud context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.