
GIAC Critical Controls Certification
Domain 6Objective 1
Application Software Security GCCC Practice Questions (Page 11)
Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 51–53
- 51
A company is migrating a monolithic application to a microservices architecture running in Kubernetes. The security team wants to ensure that the migration does not introduce new vulnerabilities. Which practice should the team implement during the migration?
Select an answer first - 52
A security engineer is reviewing a Java application that deserializes objects received from a message queue. The application uses Java's native serialization. A SAST scan flags the deserialization as insecure. The application is critical and cannot be taken offline for a rewrite. Which remediation should the engineer prioritize?
Select an answer first - 53
A development team is migrating a legacy application to a modern framework. The application currently uses XML to transfer data between services. A security review identifies that the XML parser is vulnerable to XXE (XML External Entity) attacks. The team must fix this without breaking existing functionality. Which approach is most effective?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCCC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.