
GIAC Security Essentials
Domain 1Objective 3
Security Frameworks and CIS Controls GSEC Practice Questions (Page 3)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 11–15
- 11
Which of the following CIS Controls is classified as an Organizational control?
Select an answer first - 12
A small business is implementing the CIS Controls and wants to focus on the controls that mitigate the most common attacks. Which of the following controls are part of the CIS Controls' Basic category? Select all that apply.
Select an answer first - 13
A large financial institution with a dedicated security team and a high-risk profile is implementing the CIS Controls. They have already completed IG1 and IG2 controls and are now considering IG3. Which additional capability is most characteristic of IG3?
Select an answer first - 14
Which CIS Implementation Group is appropriate for an organization that has moderate resources and needs to implement additional controls to protect against more sophisticated threats?
Select an answer first - 15
A community college with a small IT staff wants to improve its security posture against the most common attacks, such as phishing and web-based exploits. They have limited budget and cannot implement all 18 CIS Controls immediately. Which approach aligns with the purpose of the CIS Controls?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.