
GIAC Information Security Professional
Domain 3Objective 1
Identity and Access Management (IAM) GISP Practice Questions (Page 9)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 41–45
- 41
Which standard is commonly used for exchanging authentication and authorization data between identity providers and service providers in federated identity management?
Select an answer first - 42
A company is designing a new identity management system. The system must support both employee and customer identities, and it must allow customers to use social logins (e.g., Google, Facebook) while employees use corporate credentials. The system also needs to maintain a single identity record for each user across both contexts. Which architecture best meets these requirements?
Select an answer first - 43
What is the purpose of monitoring privileged account activity?
Select an answer first - 44
Which principle requires that users be granted only the minimum permissions necessary to perform their job functions?
Select an answer first - 45
An employee is on long-term medical leave. Their manager requests that the employee's access be temporarily suspended but not deleted. The company uses automated provisioning. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.