
GIAC Critical Controls Certification
Domain 5Objective 2
Continuous Vulnerability Management GCCC Practice Questions (Page 10)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 46–49
- 46
In the vulnerability management lifecycle, what is the primary purpose of the 'classify' step?
Select an answer first - 47
A security team has completed a vulnerability assessment and found several critical vulnerabilities. Before beginning remediation, management wants to know which vulnerabilities are actually exploitable by an attacker. Which activity provides this information?
Select an answer first - 48
A security team needs to scan a large enterprise network that includes both on-premises and cloud workloads. The team wants to minimize the risk of disrupting production systems while ensuring that all assets are covered. Which scanning strategy is most appropriate?
Select an answer first - 49
A critical legacy application cannot be patched for a known remote code execution vulnerability because the vendor no longer provides updates. The application is only accessible internally by a small group of users. Which compensating control is most appropriate?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCCC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.