
GIAC Critical Controls Certification
Domain 5Objective 2
Continuous Vulnerability Management GCCC Practice Questions (Page 7)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 31–35
- 31
A company has a vulnerability management program that scans quarterly, but new critical vulnerabilities are often discovered between scans. The security team wants to reduce the window of exposure. Which change is most effective?
Select an answer first - 32
A vulnerability management team needs to report progress to executives who want to see whether the organization is reducing risk over time. Which metric is most meaningful for this purpose?
Select an answer first - 33
Which factor is most important when prioritizing vulnerabilities for remediation?
Select an answer first - 34
A security team needs to scan a mix of cloud-hosted virtual machines and on-premises servers. The cloud VMs are ephemeral and can be terminated at any time. The team wants to ensure that all VMs are scanned at least once before they are terminated. Which approach is most reliable?
Select an answer first - 35
Which activity is characteristic of a penetration test but NOT of a typical vulnerability assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.