
GIAC Information Security Professional
Domain 3Objective 3
Software Development Security GISP Practice Questions (Page 3)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 11–15
- 11
Which secure coding practice is most effective at preventing SQL injection attacks when building a database query with user-supplied input?
Select an answer first - 12
A DevOps team wants to integrate security testing into their CI/CD pipeline without slowing down development. They currently run unit tests and build artifacts. Which approach best balances security and speed?
Select an answer first - 13
A security-focused code review is being conducted on a Python web application. The reviewer finds that the application uses the `eval()` function on data received from an HTTP request. Which of the following is the most appropriate recommendation?
Select an answer first - 14
Which threat modeling technique involves drawing a data flow diagram (DFD) to identify trust boundaries, data flows, and entry points, then systematically applying a set of threat categories to each element?
Select an answer first - 15
A security architect is leading a threat modeling exercise for a new online payment application. The team has drawn a data flow diagram showing that the application accepts payment card data from users, processes it through a middleware service, and stores it in a database. The architect wants to prioritize threats based on risk. Which approach best aligns with threat modeling principles?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.