Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Professional

Domain 3Objective 3

Software Development Security GISP Practice Questions (Page 5)

Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
9concepts

Questions 21–25

  1. 21foundation · easy

    In a traditional Waterfall Software Development Life Cycle (SDLC), at which phase is it most appropriate to first formally integrate security requirements and perform threat modeling?

    Select an answer first
  2. 22application · medium

    A DevOps team wants to incorporate security testing into their CI/CD pipeline without slowing down the build process significantly. They need to catch common coding flaws early and also check for known vulnerabilities in third-party libraries. Which combination of automated checks would best achieve this?

    Select an answer first
  3. 23expert · hard

    A development team is writing a C++ application that processes untrusted binary data. A code review identifies a potential buffer overflow in a function that copies data into a fixed-size array. The team is under pressure to release quickly. Which remediation is most secure and practical?

    Select an answer first
  4. 24application · medium

    An organization is preparing to release a new version of its web application. The release process currently involves manually copying files to production servers and running database scripts by hand. The security team wants to ensure that the deployment is secure and repeatable. Which practice should be implemented first?

    Select an answer first
  5. 25application · medium

    A project manager is planning a new software project and wants to integrate security throughout the SDLC. The team is currently gathering requirements. Which security activity is most appropriate for this phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.