Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 6Objective 1

Application Software Security GCCC Practice Questions (Page 3)

Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 11–15

  1. 11expert · hard

    A security team must choose a testing strategy for a critical application that has both a legacy SOAP API and a new REST API. The team has limited budget and must identify vulnerabilities before release. Which strategy provides the best coverage within the constraint?

    Select an answer first
  2. 12expert · hard

    A team is threat modeling a new REST API that allows partners to submit bulk order files via a public endpoint. The file is parsed server-side and the results are stored in a database. The team has identified that the parser has a known buffer-overflow vulnerability that cannot be patched immediately. The API also has an endpoint that returns order status based on a user-supplied order ID. Which threat-modeling outcome should drive the immediate remediation priority?

    Select an answer first
  3. 13application · medium

    A development team is building a web application that accepts user-uploaded profile images. During a code review, a developer suggests using the file extension to determine the image type and then serving the file directly from the same domain. The security lead wants to reduce the risk of stored XSS and malicious file execution. Which combination of controls should the security lead require?

    Select an answer first
  4. 14application · medium

    A DevOps team deploys a containerized application to a Kubernetes cluster. They want to ensure that containers run with the least privilege and that images are free of known vulnerabilities. Which set of practices should they implement?

    Select an answer first
  5. 15expert · hard

    A company runs a containerized application in production. They want to improve security without slowing down deployments. The team is considering adding image scanning, runtime monitoring, and network policies. Which combination is most balanced?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.