
GIAC Information Security Professional
Domain 2Objective 1
Security Architecture and Engineering GISP Practice Questions (Page 4)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
12concepts
Questions 16–20
- 16
A software development team is adopting a secure SDLC. They want to identify and remediate security flaws early in the development process, before code is deployed. Which combination of activities best achieves this goal?
Select an answer first - 17
Which design principle states that a system should be configured to deny access by default?
Select an answer first - 18
In which phase of the system development lifecycle (SDLC) should security requirements first be identified?
Select an answer first - 19
A company is implementing a new security architecture. The security team wants to ensure that no single person can approve and execute a high-value financial transaction. Which principle should be applied?
Select an answer first - 20
A company is designing a secure messaging system. They want to ensure that messages are confidential, authentic, and non-repudiable. Which combination of cryptographic mechanisms should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.