
GIAC Information Security Professional
Domain 1Objective 1
Security and Risk Management GISP Practice Questions (Page 5)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 21–25
- 21
What is the primary goal of business continuity planning (BCP)?
Select an answer first - 22
An organization is developing a new security policy for remote work. The policy must be enforceable and support the business goal of flexible work arrangements. Which element is most important to include in the policy?
Select an answer first - 23
Which step in the risk management process involves evaluating the likelihood and impact of identified risks to determine their level of risk?
Select an answer first - 24
Which type of security document provides the specific technical details or mandatory requirements for implementing a security control?
Select an answer first - 25
A security manager is developing a dashboard for the executive team. The dashboard should show the effectiveness of the security program. The executives are busy and prefer a small number of key performance indicators (KPIs). Which set of metrics would be most useful for the executives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.