Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Professional

Domain 3Objective 2

Security Assessment and Testing GISP Practice Questions (Page 6)

Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
7concepts

Questions 26–30

  1. 26expert · hard

    An organization is subject to a regulation that requires annual security audits. The internal audit team has found several control deficiencies, but the organization has already started remediation. The external auditor is due to issue a report next month. What should the organization do?

    Select an answer first
  2. 27expert · hard

    A penetration test report includes a critical finding that was successfully exploited, a high finding that could not be exploited due to time constraints, and several medium findings. Management wants to know which findings should be fixed first. What is the best recommendation?

    Select an answer first
  3. 28foundation · easy

    What is the primary goal of a vulnerability assessment?

    Select an answer first
  4. 29application · medium

    A security analyst is asked to validate whether a newly deployed web application's authentication mechanism can be bypassed under real-world conditions. The organization has a strict change-management policy that prohibits any activity that could disrupt production systems, and the application is currently in active use by customers. The analyst must produce evidence of the actual exploitability of the authentication flaw, not just its presence. Which approach best satisfies the requirement?

    Select an answer first
  5. 30application · medium

    A security analyst has completed a vulnerability scan of the corporate network. The scanner reported 500 vulnerabilities, but the analyst knows that many are false positives or are in low-risk areas. What should the analyst do before reporting these findings to management?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.