Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Professional

Domain 3Objective 1

Identity and Access Management (IAM) GISP Practice Questions (Page 2)

Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 6–10

  1. 6expert · hard

    A company is implementing single sign-on (SSO) for its employees across multiple SaaS applications. The security team requires that the SSO solution support multi-factor authentication (MFA) and provide detailed audit logs of who accessed which application and when. The company also wants to minimize the number of times users have to enter their credentials. Which approach best meets these requirements?

    Select an answer first
  2. 7expert · hard

    A financial institution is required to enforce separation of duties (SoD) in its trading system. The system currently uses role-based access control (RBAC), but the compliance team has found that some users have conflicting roles that allow them to both enter and approve trades. The institution wants to automate the detection and prevention of such conflicts. Which approach is most effective?

    Select an answer first
  3. 8expert · hard

    A company is implementing multi-factor authentication (MFA) for all remote access to its corporate network. The security team is concerned about phishing attacks that can bypass SMS-based MFA. They also want to ensure that the MFA solution is user-friendly and does not require additional hardware for all employees. Which MFA method best addresses the phishing concern while balancing usability?

    Select an answer first
  4. 9application · medium

    A company is implementing a new financial system and wants to ensure that no single employee can both create a vendor and approve a payment to that vendor. Which IAM governance principle is being enforced?

    Select an answer first
  5. 10application · medium

    A database administrator needs to grant a reporting analyst the ability to run SELECT queries on a specific table, but the analyst should not be able to modify the table structure or data. Which SQL command should the administrator use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.