
GIAC Information Security Professional
Domain 1Objective 1
Security and Risk Management GISP Practice Questions (Page 10)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 46–50
- 46
A healthcare organization is onboarding a new cloud-based billing vendor that will process protected health information (PHI). The organization's compliance team requires assurance that the vendor meets HIPAA obligations. Which action should the organization take FIRST?
Select an answer first - 47
A security analyst detects unusual network traffic indicating a possible data exfiltration. The incident response plan requires immediate containment. Which action should the analyst take FIRST?
Select an answer first - 48
Which of the following is a common activity in third-party risk management?
Select an answer first - 49
A manufacturing company is implementing a new security policy for remote access. The policy states that all remote connections must use multi-factor authentication (MFA). The IT help desk reports that many employees are struggling with the new MFA app and are calling for support. The security manager wants to maintain the policy's intent while reducing friction. What is the most appropriate action?
Select an answer first - 50
A company has a mature security awareness program with monthly phishing simulations. The click rate has plateaued at 8% for the past six months. The security team wants to further reduce the click rate. Which approach is most likely to achieve a further reduction?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.