
GIAC Cyber Incident Leader
Domain 1Objective 5
Supply Chain Attacks GCIL Practice Questions (Page 2)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
5concepts
Questions 6–10
- 6
An organization is developing a response plan for a supply chain attack. They want to ensure they can effectively coordinate with external parties. Which element is most important to include in the plan?
Select an answer first - 7
A company is evaluating the impact of a potential supply chain attack. They have identified that a compromised software update could affect their production systems. The company is considering implementing a control to reduce the impact. Which control is most effective in reducing the impact of a compromised update?
Select an answer first - 8
A small business uses a popular accounting software package. The software vendor's update server is compromised, and a malicious update is pushed to all customers. The business installs the update and later discovers that their financial data has been exfiltrated. Which statement best describes why this is considered a supply chain attack?
Select an answer first - 9
Which of the following is an example of continuous monitoring to detect supply chain attacks?
Select an answer first - 10
Which of the following is a common vector for a supply chain attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.