
GIAC Information Security Professional
Domain 3Objective 3
Software Development Security GISP Practice Questions (Page 9)
Part of the Access, Testing, and Development domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~29–50 in this domain), expect 10–17 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 41–45
- 41
A security architect is leading a threat modeling exercise for a new online payment application. The team has identified that an attacker could modify the price of an item by tampering with a hidden form field. Which threat modeling technique would most directly help the team systematically identify and rank this and similar threats?
Select an answer first - 42
A threat modeling exercise for a financial application identifies a high-risk threat: an attacker could tamper with transaction amounts in transit. The team is considering two mitigations: (1) encrypting all traffic with TLS, and (2) implementing message authentication codes (MACs) on transaction data. The application already uses TLS for all communications. What is the most appropriate conclusion?
Select an answer first - 43
A DevOps team is implementing a DevSecOps pipeline for a microservices application. They want to ensure that security testing is automated and does not become a bottleneck. The team has a limited budget and cannot afford expensive commercial tools. Which combination of practices is most effective?
Select an answer first - 44
What is the primary security goal when decommissioning a software system or disposing of its storage media?
Select an answer first - 45
During a code review, a developer notices that a web application constructs SQL queries by concatenating user input directly into the query string. The application is written in Java and uses a relational database. Which remediation is the most effective secure coding practice to prevent SQL injection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISP” is a trademark of its owner, used for identification only.