
GIAC Information Security Professional
Domain 3Objective 2
Security Assessment and Testing GISP Practice Questions (Page 3)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 11–15
- 11
Which of the following is a typical output of a security audit?
Select an answer first - 12
In a vulnerability assessment, what does 'prioritizing' vulnerabilities typically involve?
Select an answer first - 13
A security team has a budget to test only 5 of 20 systems this year. The systems include a public web server, an internal file server, a development database, a legacy application used by a small team, and a new cloud-based customer relationship management (CRM) system. Which systems should be tested first?
Select an answer first - 14
In risk-based testing, which factor is typically considered when prioritizing a test area?
Select an answer first - 15
After a vulnerability assessment, the security team has a list of 200 findings. Management wants a report that clearly shows which vulnerabilities pose the greatest risk to the organization and what actions are needed. What is the most effective way to present this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.