
GIAC Cyber Incident Leader
Domain 1Objective 5
Supply Chain Attacks GCIL Practice Questions (Page 7)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
5concepts
Questions 31–35
- 31
A manufacturing company uses a specialized industrial control system (ICS) vendor for its assembly line. The vendor releases a critical security patch for the ICS software. The company's IT manager wants to verify the patch's authenticity before deployment. Which action provides the strongest assurance that the patch is legitimate and unmodified?
Select an answer first - 32
A government contractor discovers that a hardware component in its new servers was intercepted during shipping and replaced with a counterfeit that includes a hidden backdoor. Which supply chain attack vector does this scenario describe?
Select an answer first - 33
A financial services firm relies on a SaaS provider for customer relationship management. The firm's security team wants to implement a practical supply chain risk management control that addresses the provider's security posture. Which action is most aligned with vendor risk management best practices?
Select an answer first - 34
A company's security team is investigating a potential supply chain attack. They have identified that a software library used in their application was recently updated, and the new version contains suspicious code. The update was downloaded from the vendor's official repository. Which action should the team take first?
Select an answer first - 35
A company is evaluating its supply chain risk management program. The company uses a critical SaaS provider for email and collaboration. The provider has a strong security program but has suffered two minor outages in the past year. The company's leadership wants to reduce the risk of a supply chain attack without significantly increasing costs. Which approach is most balanced?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.