
GIAC Information Security Professional
Domain 2Objective 1
Security Architecture and Engineering GISP Practice Questions (Page 7)
Part of the Security Architecture and Operations domain, which makes up ~43% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~41–69 in this domain), expect 14–23 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
12concepts
Questions 31–35
- 31
A software development team is adopting a secure SDLC. They want to identify vulnerabilities early in the development process, ideally before code is committed to the repository. Which practice should they implement?
Select an answer first - 32
Which type of security control is designed to stop an attack before it occurs?
Select an answer first - 33
A development team is building a web application that accepts file uploads from users. The application will store the files on a server and later serve them back to other users. Which secure coding practice is most important to prevent a stored cross-site scripting (XSS) attack?
Select an answer first - 34
What is the purpose of a certificate revocation list (CRL)?
Select an answer first - 35
A company needs to ensure that a software update downloaded from their vendor is authentic and has not been tampered with during transit. Which cryptographic mechanism should be used to verify the update's origin and integrity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.