
GIAC Cyber Incident Leader
Domain 2Objective 3
Vulnerability and Threat Management GCIL Practice Questions (Page 9)
Part of the Incident Preparation and Prevention domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 41–45
- 41
An organization is migrating a legacy application to the cloud. The security team wants to identify potential threats introduced by the new architecture, such as misconfigured storage and excessive permissions. Which threat modeling approach would be most effective?
Select an answer first - 42
A security team is planning a vulnerability scan of a large enterprise network that includes both critical production systems and low-priority development environments. The scan must not cause any downtime. Which scanning strategy best balances coverage and risk?
Select an answer first - 43
What is a key characteristic of an effective vulnerability report for technical stakeholders?
Select an answer first - 44
Which factor is most important when prioritizing which vulnerability to remediate first?
Select an answer first - 45
A mid-sized company has completed a vulnerability assessment and identified 200 findings. The incident leader must communicate the results to the IT operations team, which is responsible for patching. The team has limited capacity and needs clear guidance on what to fix first. Which communication approach would best support the IT operations team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.