
GIAC Critical Controls Certification
Domain 1Objective 1
Background on CIS Controls, Standards, and Governance GCCC Practice Questions (Page 5)
Part of the Foundations and Governance domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 21–25
- 21
A financial regulator is examining a bank's cybersecurity program. The bank has implemented the CIS Controls and uses them for internal risk management. The regulator asks how the bank demonstrates that its security controls are effective. Which practice best satisfies the regulator's expectation?
Select an answer first - 22
Which of the following is a major structural change introduced in CIS Controls v8 compared to v7.1?
Select an answer first - 23
What is the purpose of Implementation Groups (IGs) in the CIS Controls?
Select an answer first - 24
A hospital system is developing its annual cybersecurity strategy. The board wants to ensure that security investments align with patient safety and operational continuity. The CISO proposes using the CIS Controls as the foundation. Which action best demonstrates the integration of cybersecurity governance with organizational objectives?
Select an answer first - 25
In what way do the CIS Controls assist with compliance reporting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.