
GIAC Information Security Professional
Domain 3Objective 2
Security Assessment and Testing GISP Practice Questions (Page 7)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 31–33
- 31
What is the primary role of a security audit?
Select an answer first - 32
What is a key difference between penetration testing and vulnerability assessment?
Select an answer first - 33
An organization is preparing for a regulatory audit. The security manager must ensure that the organization's security controls are documented and that evidence of their effectiveness is available. The manager has a limited time to prepare and must decide whether to conduct an internal audit or hire an external auditor. The internal team knows the systems well, but the external auditor provides independence. The organization has a history of internal teams overlooking issues due to familiarity. What is the most appropriate decision?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GISP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.