
GIAC Information Security Professional
Domain 1Objective 1
Security and Risk Management GISP Practice Questions (Page 12)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 56–58
- 56
In the incident management lifecycle, which phase involves identifying that an incident has occurred and determining its scope?
Select an answer first - 57
A university is classifying its data assets. The registrar's office holds student transcripts, the athletics department holds game-day photos, and the IT department holds network configuration files. Which asset should be classified as the highest sensitivity and receive the most restrictive controls?
Select an answer first - 58
Which security management framework is specifically designed to help organizations manage and reduce cybersecurity risk by providing a common language and a set of best practices based on five core functions?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GISP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.