
GIAC Information Security Professional
Domain 1Objective 1
Security and Risk Management GISP Practice Questions (Page 2)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 6–10
- 6
What is the primary purpose of third-party risk management (TPRM)?
Select an answer first - 7
When an organization decides to discontinue a business process because the associated risk is too high, which risk response strategy is being applied?
Select an answer first - 8
What is the primary purpose of security governance in an organization?
Select an answer first - 9
Which term refers to the maximum amount of time that a business process can be unavailable before its recovery becomes impossible or unacceptable?
Select an answer first - 10
An organization is defining security roles and responsibilities. The goal is to ensure accountability for security decisions and actions. Which assignment of responsibilities is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.