Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Information Security Professional

GISP

The GIAC Information Security Professional (GISP) certification validates a practitioner's understanding of the eight domains of cybersecurity knowledge that form the critical foundation of the CISSP® exam. Designed for security professionals, system and network administrators, and security managers, GISP demonstrates broad security domain fluency and offers a pragmatic alternative to CISSP, signaling expertise validated by a respected provider.

429 practice questions · Updated 2026-07-30

3Domains
8Objectives
81Concepts
429Questions

GISP Curriculum

Every domain, objective, and concept the GISP exam measures.

Security and Risk Management

14 concepts · 58 questions
  1. Security Management Frameworks
  2. Risk Management Process
  3. Risk Assessment Methods
  4. Risk Response Strategies
  5. Security Policies and Procedures
  6. Security Governance
  7. Compliance and Legal Requirements
  8. Business Continuity and Disaster Recovery
  9. Security Awareness and Training
  10. Incident Management
  11. Security Metrics and Reporting
  12. Asset Management
  13. Third-Party Risk Management
  14. Security Roles and Responsibilities

Asset Security

7 concepts · 51 questions
  1. Asset Identification and Classification
  2. Asset Inventory Management
  3. Data Classification and Handling
  4. Information Lifecycle Management
  5. Privacy and Data Protection
  6. Ownership and Custodianship
  7. Asset Retention and Disposal

Security Architecture and Engineering

12 concepts · 65 questions
  1. Security Architecture Principles
  2. Security Models
  3. System Security Engineering
  4. Secure System Design
  5. Cryptographic Concepts
  6. Public Key Infrastructure (PKI)
  7. Identity and Access Management (IAM)
  8. Security Controls
  9. Secure Network Architecture
  10. Secure Software Architecture
  11. Security Evaluation and Assurance
  12. Physical Security Integration

Security Operations

12 concepts · 62 questions
  1. Security Operations Center (SOC) Roles and Responsibilities
  2. Incident Response Lifecycle
  3. Security Monitoring and Log Management
  4. Threat Intelligence and Indicators of Compromise (IoCs)
  5. Vulnerability Management and Patching
  6. Security Information and Event Management (SIEM)
  7. Intrusion Detection and Prevention Systems (IDPS)
  8. Endpoint Detection and Response (EDR)
  9. Security Orchestration, Automation, and Response (SOAR)
  10. Incident Triage and Escalation
  11. Forensics and Evidence Handling
  12. Business Continuity and Disaster Recovery in Operations

Communication and Network Security

12 concepts · 58 questions
  1. Network Security Fundamentals
  2. OSI and TCP/IP Models
  3. Secure Network Protocols
  4. Network Attacks and Countermeasures
  5. Network Segmentation and Isolation
  6. Firewalls and Intrusion Detection/Prevention
  7. Virtual Private Networks (VPNs)
  8. Wireless Network Security
  9. Network Access Control (NAC)
  10. Secure Communication Channels
  11. Network Monitoring and Logging
  12. Cloud and Virtual Network Security

Identity and Access Management (IAM)

8 concepts · 46 questions
  1. IAM Fundamentals
  2. Authentication Methods
  3. Authorization Models
  4. Identity Lifecycle Management
  5. Federated Identity and SSO
  6. Privileged Access Management
  7. Access Control Implementation
  8. IAM Governance and Compliance

Security Assessment and Testing

7 concepts · 33 questions
  1. Security Assessment and Testing Overview
  2. Vulnerability Assessment
  3. Penetration Testing
  4. Security Audits
  5. Security Testing Techniques
  6. Risk-Based Testing
  7. Reporting and Remediation

Software Development Security

9 concepts · 56 questions
  1. Secure SDLC
  2. Threat Modeling
  3. Secure Coding Practices
  4. Security Testing
  5. Code Review
  6. Software Deployment Security
  7. DevSecOps
  8. Software Supply Chain Security
  9. Secure Maintenance and Disposal
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GISP, so none is invented.