
GIAC Information Security Professional
Domain 1Objective 1
Security and Risk Management GISP Practice Questions (Page 11)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 51–55
- 51
A company's board of directors wants to ensure that security investments are aligned with business objectives and regulatory requirements. Which governance mechanism would be most effective?
Select an answer first - 52
Which role is typically responsible for the day-to-day implementation and enforcement of an organization's security policies?
Select an answer first - 53
A security team is developing metrics to report to the board. The board wants to understand the organization's overall security posture and the effectiveness of the security program. Which combination of metrics would provide the most balanced view?
Select an answer first - 54
An organization decides to purchase cyber insurance to cover potential losses from a data breach. Which risk response strategy is this?
Select an answer first - 55
A security analyst is performing a risk assessment for a new customer portal. The analyst identifies that the portal is exposed to the internet and could be targeted by brute-force attacks. After evaluating the likelihood and impact, the analyst determines the risk is high. Which step should the analyst take next in the risk management process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.