
GIAC Information Security Professional
Domain 3Objective 3
Software Development Security GISP Practice Questions (Page 4)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 16–20
- 16
An organization is decommissioning an internal application that stored sensitive customer data. The application server will be repurposed for a different, non-sensitive workload. What is the most important step to take before repurposing the server?
Select an answer first - 17
A threat modeling session for a new IoT device management platform identifies that the device authentication mechanism relies on a shared static key embedded in the firmware. The team wants to reduce the risk of key compromise. Which mitigation is most aligned with threat modeling outcomes?
Select an answer first - 18
Which practice is essential for ensuring that deployed software is configured securely and consistently across environments?
Select an answer first - 19
What is the primary purpose of patch management in the context of software deployment security?
Select an answer first - 20
Which coding practice is the primary defense against cross-site scripting (XSS) when rendering user-supplied data in a web page?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.