
GIAC Critical Controls Certification
Domain 1Objective 2
Service Provider Management GCCC Practice Questions (Page 7)
Part of the Foundations and Governance domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 31–35
- 31
Which security clause is essential to include in a contract with a service provider?
Select an answer first - 32
A healthcare organization is evaluating a cloud-based email encryption vendor that will process protected health information (PHI). The vendor has provided a SOC 2 Type II report, but the organization's compliance team notes the report does not include a HIPAA-specific attestation. During the pre-engagement assessment, which action is most important before signing the contract?
Select an answer first - 33
A company is considering outsourcing its email security to a third-party provider. The security team is concerned about maintaining visibility into the provider's security controls. Which approach best supports the company's security and compliance needs?
Select an answer first - 34
A company's SaaS vendor has suffered a ransomware attack that has encrypted the vendor's systems, including the company's data. The company's own systems are unaffected. What should the company do first?
Select an answer first - 35
Which activity is a core component of service provider management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.