
GIAC Information Security Professional
Domain 3Objective 3
Software Development Security GISP Practice Questions (Page 10)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 46–50
- 46
A company is deploying a new version of its web application to production. The deployment pipeline is automated, but the security team is concerned about misconfigurations and unpatched components. Which practice should be integrated into the deployment process to address these concerns?
Select an answer first - 47
A company is developing a mobile application that uses a third-party SDK for analytics. The SDK is known to collect user data and transmit it to the vendor's servers. The company's privacy policy states that user data is not shared with third parties. The legal team is concerned about compliance. What is the most appropriate action?
Select an answer first - 48
During a security-focused code review, a reviewer finds that a web application uses a JavaScript function to validate user input on the client side, but the server does not perform any validation. The application accepts user comments and displays them to other users. What is the most important issue to address?
Select an answer first - 49
A software company uses a third-party component in its product. The component's maintainer announces that they will no longer provide security updates. The company's product is widely deployed and cannot be easily replaced. What is the most appropriate risk mitigation?
Select an answer first - 50
A security code review is being conducted on a Java web application. The reviewer finds that the application uses a custom authentication filter that checks if a user is in a hardcoded list of admin usernames. The filter is applied to all requests except static resources. Which of the following is the most significant security flaw in this design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.