
GIAC Information Security Professional
Domain 1Objective 1
Security and Risk Management GISP Practice Questions (Page 6)
Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 26–30
- 26
Which of the following is a key responsibility of an organization's board of directors or senior management in security governance?
Select an answer first - 27
An organization is deciding between two risk assessment methodologies for a new project. The project team has limited historical data on the likelihood of cyber events. The risk manager needs to communicate the results to a non-technical board. Which approach is most appropriate?
Select an answer first - 28
A healthcare organization uses a third-party cloud provider to store de-identified patient data. The provider announces that it will move data to a jurisdiction with weaker data-protection laws. The organization's legal team confirms that the transfer would violate the organization's obligations under applicable privacy regulations. Which risk response strategy best aligns with the organization's compliance requirements?
Select an answer first - 29
A risk manager is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The team has identified a risk of data breach due to misconfigured cloud storage. What is the NEXT step in the risk management process?
Select an answer first - 30
Which risk assessment methodology uses numerical values, such as monetary amounts and percentages, to calculate risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.