
GIAC Information Security Professional
Domain 2Objective 3
Communication and Network Security GISP Practice Questions (Page 5)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 21–25
- 21
A security analyst is investigating a suspected ARP spoofing attack on a wired LAN segment. The analyst wants to confirm the attack and then implement a mitigation that does not disrupt legitimate traffic. Which combination of actions should the analyst take?
Select an answer first - 22
A company is migrating a multi-tier application to a cloud environment. The security team wants to ensure that the web tier can communicate with the application tier, but the application tier cannot initiate connections to the web tier. They also want to isolate each tier from the others. Which cloud networking approach should they use?
Select an answer first - 23
What is the primary function of a firewall?
Select an answer first - 24
Which type of network attack involves an attacker intercepting and reading data as it travels across a network?
Select an answer first - 25
What is the key difference between an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.