
GIAC Information Security Professional
Domain 1Objective 2
Asset Security GISP Practice Questions (Page 7)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 31–35
- 31
A large corporation is defining roles for its new data governance program. The CISO has been assigned responsibility for ensuring that data is protected according to its classification. The business unit managers have been assigned responsibility for determining the classification of their data. Which role does the CISO fulfill?
Select an answer first - 32
A multinational company collects customer data in the European Union and transfers it to a data center in the United States for processing. The company's privacy team is concerned about compliance with GDPR. What is the most important control to implement?
Select an answer first - 33
A healthcare organization is implementing a data classification scheme. They need to label patient health records, employee HR files, and cafeteria menus. What is the most appropriate classification for patient health records?
Select an answer first - 34
Which of the following is a common privacy regulation that governs the handling of PII?
Select an answer first - 35
An organization is developing a classification scheme for its information assets. Which factor is most directly used to determine the classification level of an asset?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.