GIAC GISP Certification Sample Questions

GISP Dumps, GISP PDF, GISP VCE, GIAC Information Security Professional VCE, GIAC GISP PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Information Security Professional (GISP) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GISP certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GISP Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Information Security Professional (GISP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Information Security Professional exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GISP Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GISP Sample Questions:

01. A researcher creates a document on a system where every subject holds a clearance and every object carries a label. A colleague working on the same project asks the researcher for access to it.
What can the researcher do?
a) Nothing, since the system alone decides access by comparing labels against clearances.
b) Grant read access, since discretion over the object is held by its creator.
c) Grant read access, since the colleague shares the same project role.
d) Grant read access, since the creator may lower the object's label.
 
02. Three biometric devices are proposed. Device A publishes a false rejection rate of 2 percent at a stated sensitivity, Device B publishes a false acceptance rate of 0.5 percent at a different sensitivity, and Device C publishes a crossover error rate of 1.2 percent.
What can be concluded from those figures?
a) Device C is the least accurate, since its published error rate is the highest of the three.
b) Nothing comparative, since only one figure is expressed independently of the sensitivity chosen.
c) Device B is the most accurate, since its published error rate is the lowest of the three.
d) Device A is the most usable, since its published rate concerns rejection of legitimate users.
 
03. A perimeter device applies one set of restrictions to every request arriving between eight in the evening and six in the morning, irrespective of who the requester is or what they do in the organization.
How is that control classified?
a) Rule-based, since the same conditions apply to every subject alike.
b) Attribute-based, since the request's timing is evaluated dynamically on arrival.
c) Discretionary, since the device owner configures the restriction at their discretion.
d) Role-based, since the restriction is administered as one collective assignment.
 
04. A university wants its staff to reach a research service run by a partner institution using their own university credentials, without the partner ever holding or seeing those credentials.
What does the arrangement require?
a) Credential synchronization, in which passwords are replicated into the partner's store.
b) Single sign-on, in which one authentication event covers the university's internal systems.
c) A shared directory, in which both institutions maintain the same account records.
d) Federation, in which the partner accepts an assertion issued by the university.
 
05. A bank proposes to strengthen customer sign-in by requiring a password and then two personal security questions before the session opens.
Why does that proposal fail to deliver multi-factor authentication?
a) All three challenges draw on something the customer knows.
b) Security question answers are often available from public records.
c) Possession of the customer's registered device is never confirmed.
d) Three challenges issued by one provider share a single point of compromise.
 
06. Three administrators share a single privileged account on a database platform. Each signs in with the same password, and the platform records every action against that one account name.
Which of the four access-control steps has been defeated?
a) Authentication, because the password cannot prove who presented it.
b) Identification, because the administrators never claim an identity at all.
c) Accountability, because no recorded action can be attributed to an individual person.
d) Authorization, because the account holds more rights than one duty needs.
 
07. During a malware outbreak an analyst has confirmed which hosts are infected and has identified the mechanism the malware uses to spread across the internal network.
Which phase must be completed before the malware is removed from the affected hosts?
a) Containment, which halts the spread across the network.
b) Preparation, which readies the response capability.
c) Lessons learned, which revises the readiness.
d) Recovery, which returns hosts to service.
 
08. A merger announcement was classified at the organization's highest internal level while it remained confidential. The announcement was published to the market this morning.
What should happen to the document's classification?
a) The custodian removes the markings, and the storage controls are relaxed accordingly
b) The level stands, and a public version is issued separately from the marked original
c) The owner formally downgrades it, and the handling requirements change accordingly
d) The level stands, and the markings remain until the retention period expires
 
09. An analytics team removes names and account numbers from a dataset, leaving postcode, date of birth and gender, and proposes releasing it to a partner as non-personal data.
What is the flaw in the proposal?
a) The removal was performed on a copy, so the original still carries the identifiers
b) The remaining fields can still single out an individual, so the data is personal
c) The remaining fields exceed what the partner's stated purpose actually requires
d) The removed fields were the only ones covered by the partner's contractual restriction
 
10. After a user emailed a customer list to a personal account, a manager proposes deploying data loss prevention and states that it will remove the need to review who can reach the customer database.
What is wrong with that reasoning?
a) It would not have detected this transfer, which used an ordinary business channel
b) It needs the data classified first, and this organization has not yet done that
c) It watches data movement and does not decide who may reach the database
d) Its coverage stops at the monitored channels, so any unmonitored path remains open

Answers:

Question: 01
Answer: a
Question: 02
Answer: b
Question: 03
Answer: a
Question: 04
Answer: d
Question: 05
Answer: a
Question: 06
Answer: c
Question: 07
Answer: a
Question: 08
Answer: c
Question: 09
Answer: b
Question: 10
Answer: c

Note: For any error in GIAC Information Security Professional (GISP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (83 votes)