GIAC · Information Security Fundamentals GISF

GIAC Information Security Fundamentals GISF Exam Practice Questions

316 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 316 questions in this pack

Question 1

Your company is covered under a liability insurance policy, which provides various liability coverage for information security risks, including any physical damage of assets, hacking attacks, etc. Which of the following risk management techniques is your company using?

  1. Risk acceptance
  2. Risk transfer
  3. Risk avoidance
  4. Risk mitigation
Show answer and explanation

Correct answer: B. Risk transfer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance. By obtaining liability insurance that covers information security risks including hacking attacks and physical damage, the company is transferring its risk exposure to the insurance provider. The company still faces the risk, but the financial burden is transferred.

Why the other options are wrong

  • A. Risk acceptance means acknowledging the risk and choosing to absorb potential losses without mitigation or transfer.
  • C. Risk avoidance involves eliminating the activity that creates the risk entirely.
  • D. Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk.

Question 2

You have successfully installed an IRM server into your environment. This IRM server will be utilized to protect the company's videos, which are available to all employees but contain sensitive data. You log on to the WSS 3.0 server with administrator permissions and navigate to the Operations section. What option should you now choose so that you can input the RMS server name for the WSS 3.0 server to use?

  1. Self-service site management
  2. Content databases
  3. Information Rights Management
  4. Define managed paths
Show answer and explanation

Correct answer: C. Information Rights Management

Information Rights Management (IRM) is the specific feature in SharePoint/WSS 3.0 that manages rights to protected content. To configure an IRM server for WSS 3.0, administrators navigate to the Operations section and select the Information Rights Management option, where they can input the RMS server name and configure IRM settings for the farm.

Why the other options are wrong

  • A. Self-service site management controls user site creation permissions, not IRM configuration.
  • B. Content databases are used to manage the databases that store SharePoint content, not to configure external services like RMS.
  • D. Define managed paths is used to configure URL path inclusion/exclusion for managed content, not for IRM server settings.

Question 3

You work as a security manager for Qualxiss Inc. Your Company involves OODA loop for resolving and deciding over company issues. You have detected a security breach issue in your company. Which of the following procedures regarding the breach is involved in the observe phase of the OODA loop?

  1. Follow the company security guidelines.
  2. Decide an activity based on a hypothesis.
  3. Implement an action practically as policies.
  4. Consider previous experiences of security breaches.
Show answer and explanation

Correct answer: A. Follow the company security guidelines.

The Observe phase of the OODA loop is pure data collection: the manager watches the unfolding situation and gathers information through the established channels and controls already in place, which for a detected breach means working from the company security guidelines and documented reporting procedures. Analysis that draws on prior experience belongs to Orient, selecting a course of action belongs to Decide, and putting that action into effect belongs to Act. Because the question asks what happens while the breach is being observed, following the company security guidelines is the correct procedure.

Why the other options are wrong

  • B. Choosing an activity based on a hypothesis is the Decide phase, where one option is selected from the alternatives produced by orientation.
  • C. Implementing an action practically as policy is the Act phase, which executes the decision already made.
  • D. Weighing previous experiences of security breaches is the Orient phase, where observed data is filtered through prior knowledge and analysis.

See all 10 free questions Get the full pack, US$39

316 practice questions for GIAC Information Security Fundamentals (GISF), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 316 questions mapped to the GISF exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A GISF attempt costs US$499. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 316 questions

What makes the GISF hard

The GISF is GIAC’s entry exam, but entry is doing a lot of work in that sentence: it is still a GIAC test, at GIAC prices, with GIAC’s open-book time pressure.

The scope is the foundation layer: security principles and risk basics, cryptography fundamentals, network concepts and defence in depth, incident response at the awareness level, and the policy and compliance frame around it all. The questions reward precise definitions, and the wrong answers are neighbouring concepts that skim-level knowledge picks reliably.

It is 75 questions in two hours, and the pass mark moved to 69% for exam versions from 7 March 2026 onward. With only 75 questions, that is 52 correct answers, which leaves room for 23 mistakes and no more. It is the on-ramp for managers and career-changers heading toward GSEC.

About the exam

GISF certifies foundational information security knowledge: core concepts, risk, cryptography basics, network security, and incident handling awareness, as the entry point of the GIAC ladder before GSEC. Open book, proctored. Valid for four years with CPEs.

Exam topics

  • Information security concepts and principles
  • Risk management fundamentals
  • Cryptography basics
  • Network security and defence in depth
  • Incident handling and business continuity awareness

75 questions, 2 hours, passing score 69% (exam versions from 7 March 2026), open book, US$499 per attempt, valid 4 years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Information Security Fundamentals GISF pack?

316 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.