
GIAC Critical Controls Certification
Domain 6Objective 1
Application Software Security GCCC Practice Questions (Page 7)
Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 31–35
- 31
A security operations team notices a spike in 401 errors from a web application, followed by a successful login from an unusual geographic location. They suspect a credential-stuffing attack. Which immediate response action is most appropriate?
Select an answer first - 32
A security team is reviewing a Kubernetes cluster that runs multiple microservices. They want to detect anomalous behavior within containers. Which approach is most effective?
Select an answer first - 33
A threat modeling session for a healthcare application identifies that patient data is stored in a database and accessed by multiple services. The team must prioritize threats based on risk. Which threat should be addressed first?
Select an answer first - 34
A company is developing a new mobile application that processes payment information. The project is in the requirements phase. The security team wants to ensure that security is considered throughout the project. Which activity should the team perform during the requirements phase?
Select an answer first - 35
Which of the following is a security best practice for an orchestration platform like Kubernetes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.