Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Incident Leader

Domain 1Objective 5

Supply Chain Attacks GCIL Practice Questions (Page 9)

Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
5concepts

Questions 41–45

  1. 41expert · hard

    A company is reviewing its supply chain security posture. They have identified that a critical vendor uses a third-party code repository to host its software. The company is concerned about the risk of a compromised update from this repository. Which control would be most effective in mitigating this specific risk?

    Select an answer first
  2. 42expert · hard

    A company is assessing the risk of a supply chain attack on its critical infrastructure. They have identified a vendor that provides a component used in their industrial control systems. The vendor has a history of security incidents. The company is considering whether to continue using this vendor. What is the most important factor to consider in this decision?

    Select an answer first
  3. 43application · medium

    A manufacturing company learns that a firmware update for its industrial controllers, supplied by a trusted automation vendor, contains a backdoor that allows remote attackers to alter production line settings. The company's leadership asks the incident response team to prioritize the response. Which consideration should be the team's primary focus when assessing the impact of this supply chain compromise?

    Select an answer first
  4. 44foundation · easy

    Which of the following is a key component of vendor risk management to mitigate supply chain attacks?

    Select an answer first
  5. 45application · medium

    A financial services firm is reviewing its vendor risk management program after a recent supply chain attack in its industry. The firm wants to implement a proactive control that specifically targets the risk of a compromised software update from a critical vendor. Which control is most directly aligned with this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCIL

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.