GISP GIAC Information Security Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Following a severe, confirmed exfiltration of sensitive customer PII due to a novel zero-day exploit, a cybersecurity response team is engaged in mitigating the incident. The chief information security officer (CISO) is demanding immediate actionable intelligence on the attack vector and containment status, while the legal counsel is emphasizing strict adherence to data breach notification timelines mandated by the California Consumer Privacy Act (CCPA) and is concerned about potential class-action lawsuits. Simultaneously, the incident response lead is reporting difficulties in fully isolating a critical legacy system that appears to be the primary ingress point, requiring a temporary rollback of some security monitoring tools to maintain operational visibility. Considering these competing demands and the inherent ambiguity of a rapidly unfolding, zero-day event, which of the following strategic responses best exemplifies a holistic and effective approach to managing this multifaceted crisis, reflecting a strong understanding of both technical incident response and broader organizational responsibilities?

Prioritize the legal counsel's directives for immediate CCPA notification, while simultaneously tasking a specialized sub-team to develop a temporary segmentation solution for the legacy system, and initiating a parallel review of the incident response plan's effectiveness against zero-day threats.
Focus exclusively on isolating the legacy system and eradicating the threat, deferring all external communications and legal consultations until the technical containment is fully achieved and verified.
Immediately issue a public statement acknowledging the breach and its potential scope, while directing the technical team to focus solely on patching the zero-day vulnerability without regard for system availability or ongoing monitoring capabilities.
Delegate the entire incident response process to an external cybersecurity firm, allowing them to manage all technical, legal, and communication aspects, thereby minimizing internal resource strain and potential liability.

About the GISP GIAC Information Security Professional Certification

These free practice questions are designed to help you assess your readiness for the GISP GIAC Information Security Professional exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.