
GIAC Cyber Incident Leader
Domain 2Objective 3
Vulnerability and Threat Management GCIL Practice Questions (Page 1)
Part of the Incident Preparation and Prevention domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 1–5
- 1
A vulnerability assessment identified several critical vulnerabilities in different business units. The security team needs to communicate the findings to the business unit managers, who have different risk appetites and budgets. What is the most effective communication strategy?
Select an answer first - 2
A company has identified a critical vulnerability in a customer-facing application. The vulnerability is not currently exploited, but the company's threat intelligence indicates that exploitation is likely in the near future. The incident leader must communicate this finding to the executive team and recommend a course of action. The executive team is concerned about the cost of immediate remediation and the potential impact on customer experience. Which recommendation should the incident leader make?
Select an answer first - 3
A critical vulnerability is found in a legacy application that the vendor no longer supports. The application is essential to daily operations and cannot be replaced for several months. Which remediation approach is most appropriate in the interim?
Select an answer first - 4
A large e-commerce company is redesigning its payment processing system. The security team is conducting a threat modeling exercise using the STRIDE methodology. During the exercise, the team identifies a threat where an attacker could tamper with transaction data in transit between the web server and the payment gateway. The team is considering two controls: enabling TLS 1.3 with certificate pinning, and implementing a message authentication code (MAC) on the application layer. The incident leader must decide which control to prioritize. Which consideration should drive the decision?
Select an answer first - 5
A vulnerability assessment identified a SQL injection flaw in a web application. The application is behind a WAF that blocks common SQL injection payloads. How should the team evaluate the severity of this finding?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.