GIAC · Information Security Professional GISP

GIAC Information Security Professional GISP Exam Practice Questions

654 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 654 questions in this pack

Question 1

Which of the following is a technique used to attack an Ethernet wired or wireless network?

  1. DNS poisoning
  2. Keystroke logging
  3. Mail bombing
  4. ARP poisoning
Show answer and explanation

Correct answer: D. ARP poisoning

ARP poisoning is a data link layer (Layer 2) attack that sends forged Address Resolution Protocol replies so that a victim maps an attacker's MAC address to a legitimate IP address. Because ARP resolution happens on the local Ethernet segment, the attack works against both wired switched LANs and wireless LANs bridged to them. The result is traffic interception, modification, or blocking in a man-in-the-middle position.

Why the other options are wrong

  • A. DNS poisoning corrupts name resolution records or resolver caches at the application layer rather than manipulating Ethernet frame delivery on the local segment.
  • B. Keystroke logging captures input on an individual host through software or hardware and does not attack the network itself.
  • C. Mail bombing floods a mailbox or mail server with messages, which is an application layer denial-of-service technique, not an Ethernet attack.

Question 2

Which of the following refers to encrypted text?

  1. Plaintext
  2. Cookies
  3. Hypertext
  4. Ciphertext
Show answer and explanation

Correct answer: D. Ciphertext

Ciphertext is the standard term for encrypted text that has been transformed through a cryptographic algorithm. It is unreadable without the appropriate decryption key and is the output of any encryption process.

Why the other options are wrong

  • A. Plaintext refers to unencrypted, readable text before encryption is applied.
  • B. Cookies are HTTP data storage mechanisms used for session management, not encrypted text.
  • C. Hypertext is markup-formatted text for web documents, not encrypted material.

Question 3

Which of the following are the benefits of information classification for an organization?

  1. It helps identify which information is the most sensitive or vital to an organization.
  2. It ensures that modifications are not made to data by unauthorized personnel or processes.
  3. It helps identify which protections apply to which information.
  4. It helps reduce the Total Cost of Ownership (TCO).
Show answer and explanation

Correct answer: A, C

A. It helps identify which information is the most sensitive or vital to an organization. C. It helps identify which protections apply to which information. Information classification helps organizations identify which data is most sensitive or critical (option A), enabling risk assessment and prioritization. It also determines which security protections and controls should apply to different data categories (option C). Option B describes data integrity controls, and option D relates to cost management rather than classification purposes.

Why the other options are wrong

  • B. Preventing unauthorized modifications is a function of data integrity and access controls, not classification itself.
  • D. While classification may indirectly affect costs, reducing TCO is not a direct benefit of the classification process.

See all 10 free questions Get the full pack, US$39

654 practice questions for GIAC Information Security Professional (GISP), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 654 questions mapped to the GISP exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A GISP attempt costs US$999. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 654 questions

What makes the GISP hard

The GISP covers the same eight domains as the CISSP: it is GIAC’s exam over the ISC2 body of knowledge, and a lot of candidates sit it as the proctored proof-point of their CISSP preparation.

The ground is the full CBK: risk management, asset security, architecture and engineering, network security, IAM, assessment and testing, operations, and software development security. The difference is style: GIAC writes more directly technical questions than ISC2’s best-answer philosophy, and it is open book, which changes preparation completely, since a good index does half the work.

It is also the longest exam GIAC runs at this level, 150 questions in four hours, which works out at roughly 96 seconds a question. Candidates who plan to look everything up run out of clock. It draws the same audience as the CISSP question bank, one exam over.

About the exam

GISP certifies knowledge across the eight CISSP domains as defined by ISC2, risk, asset security, architecture, network security, IAM, assessment, operations, and software security, tested GIAC-style. Open book, proctored, DoD 8140 mapped. Valid for four years with CPEs.

Exam topics

  • Security and risk management, asset security
  • Security architecture and engineering
  • Communication and network security
  • Identity and access management, assessment and testing
  • Security operations and software development security

150 questions, 4 hours, passing score 70%, open book, US$999 per attempt, valid 4 years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Information Security Professional GISP pack?

654 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.