About the Exam

GISP validates understanding of the eight cybersecurity domains that GIAC says are a critical part of the CISSP exam. It is aimed at security professionals, system administrators, security administrators, network administrators, and security managers who want broad security domain fluency. Passing demonstrates competency in areas including security and risk management, asset security, network security, IAM, security assessment and testing, security operations, and software development security.

Exam Topics

  • Asset Security13%
  • Communications and Network Security13%
  • Identity and Access Management13%
  • Security Assessment and Testing13%
  • Security Engineering13%
  • Security Operation13%
  • Security and Risk Management13%
  • Software Development Security13%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 13, 2026 at 7:38 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Communications and Network Security

Which of the following devices or services functions as an intermediary between a user located on the internal network and a service that resides on an external network, such as the Internet?

  • A DNS server
  • B Firewall
  • C Proxy server
  • D WINS server
Explanation

A proxy server is designed to intercept and relay requests between internal clients and external services, effectively standing in for the client when communicating with the Internet. It can perform functions such as caching content, filtering requests, masking the client's IP address, and enforcing access policies — all characteristic of acting as an intermediary. In contrast, a firewall filters traffic based on security rules rather than acting as a go-between for service requests, while DNS and WINS servers merely perform name resolution and do not mediate communication sessions between clients and external services.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Communications and Network Security

Which term best describes an attempt to transfer DNS zone data?

  • A Reconnaissance
  • B Dumpster diving
  • C Encapsulation
  • D Spam
Explanation

Attempting a DNS zone transfer is a classic reconnaissance technique, where an attacker tries to obtain a complete copy of a DNS zone (including all hostnames, IP addresses, and subdomains) to map out the target's network infrastructure before launching further attacks. This activity falls under the reconnaissance phase of the attack lifecycle, as it involves gathering information about the target rather than exploiting a vulnerability directly.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Security Operation

Which group is most likely to be the source of an asset loss resulting from the improper or inappropriate use of computers?

  • A Visitors
  • B Customers
  • C Employees
  • D Hackers
Explanation

Employees are considered the most probable source of asset loss from computer misuse because they already possess authorized access to organizational systems, applications, and data. This inherent trust and access level makes it easier for employees—whether through negligence, error, or intentional misconduct—to cause loss of confidentiality, integrity, or availability of assets, compared to outsiders (hackers), who must first overcome external defenses to gain access, or visitors and customers, who typically have minimal or no direct access to internal computing resources. Security risk models used in frameworks such as CISSP's asset security domain emphasize that insider threats, including employees, represent the largest and most consistent risk category for asset loss due to inappropriate computer use.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Asset Security

Which of the following conditions the electrical line to keep the voltage stable and clean?

  • A Power regulator
  • B Demilitarized zone (DMZ)
  • C Transponder
  • D Smoke detector
Explanation

A power regulator controls and stabilizes voltage, helping keep the power supplied to equipment steady and clean.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Communications and Network Security

From every incoming data packet and forwards the packet to its destination?

  • A Hub
  • B Router
  • C Brouter
  • D Switch
Explanation

A switch uses the destination MAC address in a received Ethernet frame to look up the appropriate outgoing port in its MAC/CAM table and forward the frame toward its destination.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home