
GIAC Information Security Professional
Domain 2Objective 1
Security Architecture and Engineering GISP Practice Questions (Page 2)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
12concepts
Questions 6–10
- 6
A company is setting up a PKI for internal use. They want to ensure that certificates issued to employees are trusted by all internal systems. Which component should be installed on each internal system to establish this trust?
Select an answer first - 7
What is the Common Criteria (CC) used for?
Select an answer first - 8
A company is developing a new product and wants to integrate security into the SDLC. They have a limited budget and need to prioritize activities. Which activity provides the most value for identifying and fixing security flaws early?
Select an answer first - 9
A company has deployed an intrusion detection system (IDS) that generates alerts on suspicious network traffic. The security team is overwhelmed by false positives and has started ignoring alerts. Which combination of controls would best improve the effectiveness of the IDS?
Select an answer first - 10
A company is planning to deploy a PKI for internal applications. They want to minimize the risk of a compromised root CA. Which practice is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.