
GIAC Critical Controls Certification
Domain 6Objective 1
Application Software Security GCCC Practice Questions (Page 5)
Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 21–25
- 21
A small company develops a customer relationship management (CRM) application that handles sensitive client data. The company has no dedicated security team, and the developers are not security experts. The company wants to improve the security of the application without a large budget. Which approach should the company take?
Select an answer first - 22
An application displays user-generated comments on a public page. A security tester discovers that a comment containing '<script>alert(1)</script>' executes in other users' browsers. Which type of vulnerability is this, and what is the best fix?
Select an answer first - 23
A web application is behind a WAF. The security team wants to detect and block SQL injection attempts. Which WAF configuration is most appropriate?
Select an answer first - 24
Which of the following is a common technique used in threat modeling to identify potential threats?
Select an answer first - 25
What is the primary purpose of rate limiting in API security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.