
GIAC Information Security Professional
Domain 1Objective 2
Asset Security GISP Practice Questions (Page 1)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 1–5
- 1
What is the purpose of applying data classification labels to information assets?
Select an answer first - 2
An employee receives a phone call from someone claiming to be from the IT department, asking for their password to perform a 'security update'. The employee provides the password. What is the most effective control to prevent this type of incident?
Select an answer first - 3
What is the primary responsibility of an asset custodian?
Select an answer first - 4
A regional hospital is implementing a new asset management program. The IT director wants to prioritize protection efforts based on the impact of a loss. The hospital has a patient records database, a building access control system, a staff training video library, and a lobby digital signage system. Which asset should be classified as highest criticality?
Select an answer first - 5
A company is developing a new mobile app that collects user location data. The privacy team is concerned about compliance with privacy regulations. The app also needs to share location data with a third-party analytics provider. What is the most important privacy control to implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.