
GIAC Information Security Professional
Domain 2Objective 1
Security Architecture and Engineering GISP Practice Questions (Page 10)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
12concepts
Questions 46–50
- 46
Which activity is a key part of system security engineering during the design phase of the SDLC?
Select an answer first - 47
A company is implementing a PKI. They want to ensure that certificates are issued only to verified individuals and that the private keys are protected. Which combination of PKI components and practices best achieves this?
Select an answer first - 48
A company is developing a new customer-facing application. The project manager wants to ensure that security is considered throughout the development lifecycle, not just at the end. Which approach best integrates security into the SDLC?
Select an answer first - 49
Which secure coding practice helps prevent SQL injection attacks?
Select an answer first - 50
A company is designing a new application that will be accessible from the internet. They want to ensure that the application is secure by default, meaning that any feature not explicitly enabled is disabled. Which design approach best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.