
GIAC Critical Controls Certification
Domain 6Objective 1
Application Software Security GCCC Practice Questions (Page 9)
Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 41–45
- 41
A security operations team is monitoring a web application that uses a WAF. The WAF logs show a high number of requests that match a known SQL injection signature, but the requests are being blocked. The application team reports that some legitimate users are experiencing errors. What should the security team do first?
Select an answer first - 42
Which statement best describes the role of application security in protecting software?
Select an answer first - 43
What is the primary purpose of application security?
Select an answer first - 44
A DevOps team is deploying a containerized microservice to a Kubernetes cluster. The container image is built from a base image that contains several known vulnerabilities. The team wants to reduce the risk of container breakout and lateral movement. Which set of practices should the team adopt?
Select an answer first - 45
A startup is building a customer-facing application and wants to embed security from the start. They have limited resources and need to prioritize. Which action best reflects application security fundamentals?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.