
GIAC Information Security Professional
Domain 3Objective 1
Identity and Access Management (IAM) GISP Practice Questions (Page 4)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 16–20
- 16
Which of the following is an example of a possession factor for authentication?
Select an answer first - 17
Which IAM core component is primarily responsible for ensuring that user actions can be traced back to a specific individual?
Select an answer first - 18
A hospital is implementing a new policy for its physicians: they must present a badge with a chip and enter a PIN to access the medication dispensing cabinets. Which two authentication factors are being combined, and what is the primary security benefit?
Select an answer first - 19
A company wants its employees to use their existing corporate Microsoft 365 credentials to sign in to a third-party SaaS application, without the third party ever seeing the corporate password. Which federated identity standard is specifically designed for this browser-based SSO scenario?
Select an answer first - 20
A system administrator needs to perform a one-time emergency database configuration change. The company policy requires that the administrator's normal user account not have elevated rights, and that the elevated access be temporary and fully auditable. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.