
GIAC Information Security Professional
Domain 3Objective 1
Identity and Access Management (IAM) GISP Practice Questions (Page 5)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 21–25
- 21
A database administrator needs to grant a new analyst read-only access to the 'sales' schema but allow the analyst to create temporary tables in a personal schema. The database uses role-based access control. What is the most appropriate configuration?
Select an answer first - 22
A company wants to implement MFA for remote VPN access. Employees have company-issued smartphones. Which combination of authentication factors is most appropriate?
Select an answer first - 23
Your company uses Azure AD as the identity provider. You need to allow employees to access a third-party HR application using their corporate credentials. The application supports OpenID Connect. What is the primary benefit of using OpenID Connect over SAML for this integration?
Select an answer first - 24
A new employee joins the company and needs access to the HR system, the project management tool, and the corporate file share. The identity management team wants to automate the creation of the user account and the assignment of baseline permissions. Which process should be used?
Select an answer first - 25
What is the primary purpose of multi-factor authentication (MFA)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.