
GIAC Cyber Incident Leader
Domain 2Objective 3
Vulnerability and Threat Management GCIL Practice Questions (Page 6)
Part of the Incident Preparation and Prevention domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 26–30
- 26
A company is designing a new web application that will handle customer payment data. The architecture includes a public-facing load balancer, application servers, a database, and an internal admin interface. Which threat modeling approach would best help the team prioritize risks during the design phase?
Select an answer first - 27
A security team needs to identify vulnerabilities in a new containerized application environment. The environment is dynamic, with containers being created and destroyed frequently. Which approach would provide the most accurate and continuous vulnerability identification?
Select an answer first - 28
A security team is overwhelmed by the number of vulnerability alerts from multiple sources. They want to reduce noise and focus on the most relevant threats. Which approach would best achieve this?
Select an answer first - 29
What is the primary goal of a remediation plan?
Select an answer first - 30
Which vulnerability assessment output is used to communicate the relative severity of a vulnerability in a standardized, vendor-neutral way?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.