
GIAC Information Security Professional
Domain 3Objective 3
Software Development Security GISP Practice Questions (Page 2)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 6–10
- 6
Which of the following is a common focus area when conducting a security code review?
Select an answer first - 7
A DevOps team is adopting a DevSecOps approach for a containerized application. They want to automatically identify known vulnerabilities in the container images before they are deployed to the production environment. Which control should be integrated into the CI/CD pipeline?
Select an answer first - 8
A development team is building a customer-facing web application that accepts file uploads from users. During a security-focused code review, a reviewer notices that the application constructs SQL queries by concatenating user-supplied filenames directly into a database query. The team is in the coding phase of the SDLC and wants to remediate this before the next build. Which action best addresses the vulnerability while aligning with secure coding practices?
Select an answer first - 9
During the maintenance phase of a software system, which activity is essential to protect against newly discovered vulnerabilities?
Select an answer first - 10
Which practice helps mitigate supply chain risks by verifying the integrity and origin of third-party components?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.