Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 6Objective 1

Application Software Security GCCC Practice Questions (Page 6)

Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 26–30

  1. 26application · medium

    A company is designing a public API for partner integrations. They want to ensure that only authorized partners can access specific resources and that abuse is limited. Which combination of controls is most appropriate?

    Select an answer first
  2. 27foundation · easy

    Which of the following is a best practice for securing an API?

    Select an answer first
  3. 28foundation · easy

    Which of the following is a key characteristic of a secure software development lifecycle (SSDLC)?

    Select an answer first
  4. 29foundation · easy

    What is the primary purpose of input validation in secure coding?

    Select an answer first
  5. 30application · medium

    A company runs a legacy web application that cannot be patched quickly. The security team has identified that the application is vulnerable to SQL injection and cross-site scripting. The team wants to reduce the risk of exploitation while the development team works on a fix. Which control should the team implement first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.