Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Professional

Domain 1Objective 1

Security and Risk Management GISP Practice Questions (Page 7)

Part of the Security Management and Risk domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 12–20 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
14concepts

Questions 31–35

  1. 31application · medium

    An organization wants to improve its security culture by implementing a security awareness program. The program must be tailored to different employee roles and measure its effectiveness. Which approach best meets these requirements?

    Select an answer first
  2. 32expert · hard

    A global e-commerce company processes customer data in multiple regions. The company is expanding into a new country that has strict data localization requirements. The company's current cloud provider does not have a data center in that country. The legal team advises that the data must reside within the country's borders. The company is evaluating options. Which approach best balances compliance and operational continuity?

    Select an answer first
  3. 33application · medium

    A multinational corporation is adopting a security management framework to align its security program with business goals and regulatory requirements. The company operates in multiple countries with different privacy laws. Which framework would be most appropriate to provide a comprehensive, risk-based approach that can be adapted to various regulatory environments?

    Select an answer first
  4. 34foundation · easy

    In the risk management process, what is the primary purpose of the risk identification step?

    Select an answer first
  5. 35expert · hard

    A company is developing a new security policy for remote work. The policy must balance security with employee productivity. The company has a diverse workforce, including employees in different time zones and with varying technical skills. Which approach is most likely to achieve both security and usability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.