Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 6Objective 1

Application Software Security GCCC Practice Questions (Page 2)

Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 6–10

  1. 6foundation · easy

    What is the primary purpose of threat modeling in application security?

    Select an answer first
  2. 7application · medium

    A developer is writing code that queries a database using user input. The team has a policy to prevent SQL injection. Which coding practice is most effective?

    Select an answer first
  3. 8application · medium

    A security team is evaluating testing tools for a web application that has a complex JavaScript front-end and a REST API backend. They want to identify vulnerabilities that require authenticated user interactions, such as stored XSS. Which testing approach is most effective for this scenario?

    Select an answer first
  4. 9foundation · easy

    In a secure software development lifecycle (SSDLC), at which phase should security requirements be first defined?

    Select an answer first
  5. 10foundation · easy

    What is a key security consideration when using container images in a containerized application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.