Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Professional

Domain 3Objective 3

Software Development Security GISP Practice Questions (Page 6)

Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
9concepts

Questions 26–30

  1. 26foundation · easy

    Which SDLC phase typically includes activities such as code review, static analysis, and unit testing to identify and fix security flaws early?

    Select an answer first
  2. 27expert · hard

    A DevSecOps team is building a CI/CD pipeline for a microservices application. They want to automate security checks but are concerned about slowing down the pipeline. The team has a limited budget and cannot afford expensive commercial tools. They need to catch common coding flaws, known vulnerabilities in dependencies, and misconfigurations in infrastructure as code. Which approach best meets these needs within the constraints?

    Select an answer first
  3. 28expert · hard

    An organization is decommissioning a legacy application that contains sensitive data. The application runs on a physical server that is still under warranty. The organization wants to repurpose the server for a non-sensitive workload but must also comply with a data protection regulation that requires secure deletion of personal data. Which approach best satisfies both the warranty and the regulatory requirement?

    Select an answer first
  4. 29application · medium

    A security tester is performing a dynamic application security test (DAST) on a web application. The tester wants to identify vulnerabilities that require user interaction, such as stored XSS. Which testing approach is most effective?

    Select an answer first
  5. 30application · medium

    During a security code review, a reviewer notices that a C++ application uses `strcpy()` to copy user input into a fixed-size buffer. Which of the following is the most appropriate recommendation to prevent a buffer overflow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.