
GIAC Critical Controls Certification
Domain 6Objective 1
Application Software Security GCCC Practice Questions (Page 4)
Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 16–20
- 16
A company is starting a new software project and wants to integrate security into the development process from the beginning. The project manager is concerned that adding security activities will slow down the team. Which approach should the security lead recommend to balance security and speed?
Select an answer first - 17
What is the first step in an effective incident response process for an application security event?
Select an answer first - 18
What is the primary goal of application security monitoring?
Select an answer first - 19
A team is threat modeling a new payment processing application. They draw a data flow diagram and identify that cardholder data flows from the web tier to the application tier over an internal network. Which threat modeling question is most relevant to assess this flow?
Select an answer first - 20
What is the primary difference between static application security testing (SAST) and dynamic application security testing (DAST)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.