Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Security Leadership

GSLCGIAC Security Leadership (GSLC)

The GIAC Security Leadership (GSLC) certification validates your ability to lead security teams by blending practical technical controls with strategic governance. It is designed for information security managers and security professionals with leadership responsibilities who must protect, detect, and respond to security issues across the entire security lifecycle. Earning GSLC demonstrates that you can build security programs that meet business needs, manage security operations and teams, and oversee security projects from start to finish.

1002 practice questions · Updated 2026-07-30

6Domains
19Objectives
184Concepts
1002Questions

GSLC Curriculum

Every domain, objective, and concept the GSLC exam measures.

Managing Security Policy

6 concepts · 51 questions
  1. Policy Lifecycle Management
  2. Policy Development Process
  3. Policy Implementation and Communication
  4. Policy Enforcement and Compliance
  5. Policy Review and Maintenance
  6. Policy Governance and Oversight

Managing the Program Structure

10 concepts · 57 questions
  1. Program Structure Definition
  2. Governance Framework Alignment
  3. Roles and Responsibilities
  4. Program Lifecycle Management
  5. Resource Allocation
  6. Communication and Reporting
  7. Integration with Business Processes
  8. Compliance and Regulatory Considerations
  9. Performance Metrics and KPIs
  10. Continuous Improvement Mechanisms

Risk Management and Security Frameworks

7 concepts · 44 questions
  1. Risk Management Fundamentals
  2. Risk Assessment Process
  3. Risk Treatment Strategies
  4. Risk Communication and Monitoring
  5. Security Frameworks Overview
  6. Framework Implementation
  7. Governance and Compliance

Managing System Security

8 concepts · 46 questions
  1. System Security Fundamentals
  2. Security Baselines and Hardening
  3. Patch and Vulnerability Management
  4. Access Control and Identity Management
  5. System Monitoring and Auditing
  6. Incident Response and Recovery
  7. Compliance and Policy Management
  8. Secure System Lifecycle Management

Managing Network Security

10 concepts · 52 questions
  1. Network Security Fundamentals
  2. Network Threats and Vulnerabilities
  3. Network Security Controls
  4. Network Segmentation and Isolation
  5. Secure Network Architecture
  6. Network Monitoring and Analysis
  7. Incident Response for Network Security
  8. Network Security Policies and Procedures
  9. Compliance and Regulatory Requirements
  10. Emerging Network Security Technologies

Managing Cloud Security

7 concepts · 49 questions
  1. Cloud Security Fundamentals
  2. Cloud Risk Assessment
  3. Cloud Security Controls
  4. Cloud Compliance and Legal Issues
  5. Cloud Security Architecture
  6. Cloud Incident Response
  7. Cloud Vendor Management

Managing Application Security

15 concepts · 63 questions
  1. Application Security Fundamentals
  2. Secure Software Development Lifecycle (SSDLC)
  3. Threat Modeling
  4. Common Application Vulnerabilities
  5. Application Security Testing
  6. Security Requirements and Design
  7. Secure Coding Practices
  8. Application Security Controls
  9. Application Security Governance
  10. Vulnerability Management for Applications
  11. Application Security Metrics and Reporting
  12. Application Security in DevOps and Cloud
  13. Third-Party and Open Source Component Security
  14. Incident Response for Application Security
  15. Application Security Awareness and Training

Managing Artificial Intelligence

12 concepts · 61 questions
  1. AI Fundamentals
  2. AI Risk Landscape
  3. AI Governance Frameworks
  4. AI System Lifecycle Management
  5. AI Data Management
  6. AI Model Security
  7. AI Ethics and Bias
  8. AI Assurance and Auditing
  9. AI Incident Response
  10. AI Vendor and Third-Party Management
  11. AI and Organizational Strategy
  12. AI Skills and Training

Managing a Security Operations Center

6 concepts · 46 questions
  1. SOC Purpose and Functions
  2. SOC Staffing and Roles
  3. SOC Processes and Procedures
  4. SOC Technologies and Tools
  5. SOC Metrics and Performance
  6. SOC Maturity and Improvement

Network Monitoring for Managers

7 concepts · 52 questions
  1. Network Monitoring Fundamentals
  2. Key Network Monitoring Metrics
  3. Monitoring Tools and Technologies
  4. Security Monitoring vs. Performance Monitoring
  5. Interpreting Monitoring Data
  6. Alerting and Incident Response
  7. Compliance and Reporting
  1. Incident Response Lifecycle
  2. Incident Response Team Roles
  3. Incident Classification and Triage
  4. Incident Detection and Reporting
  5. Containment Strategies
  6. Eradication and Recovery
  7. Evidence Handling and Chain of Custody
  8. Communication and Coordination
  9. Post-Incident Review and Lessons Learned
  10. Business Continuity Planning Fundamentals
  11. Business Impact Analysis
  12. Continuity Strategies and Recovery Objectives
  13. Continuity Plan Development and Implementation
  14. Testing and Exercising Continuity Plans
  15. Integration of Incident Response and Business Continuity

Vulnerability Management

7 concepts · 46 questions
  1. Vulnerability Management Lifecycle
  2. Vulnerability Identification
  3. Vulnerability Assessment
  4. Risk-Based Prioritization
  5. Remediation Strategies
  6. Verification and Reporting
  7. Integration with Incident Response

Cryptography Concepts for Managers

8 concepts · 51 questions
  1. Cryptography Fundamentals
  2. Symmetric vs. Asymmetric Encryption
  3. Key Management
  4. Hashing and Digital Signatures
  5. Public Key Infrastructure (PKI)
  6. Cryptographic Attacks
  7. Cryptography in Compliance
  8. Managerial Oversight of Cryptography

Managing Encryption and Privacy

8 concepts · 47 questions
  1. Encryption Fundamentals
  2. Key Management
  3. Encryption in Transit
  4. Encryption at Rest
  5. Privacy Regulations and Compliance
  6. Data Classification and Handling
  7. Privacy by Design
  8. Incident Response for Encryption and Privacy

Managing Negotiations and Vendors

10 concepts · 58 questions
  1. Negotiation Fundamentals
  2. Negotiation Preparation
  3. Negotiation Strategies and Tactics
  4. Negotiation Communication Skills
  5. Vendor Selection Process
  6. Vendor Contracting
  7. Vendor Relationship Management
  8. Vendor Risk Management
  9. Vendor Performance Evaluation
  10. Vendor Termination and Transition

Managing Projects

24 concepts · 76 questions
  1. Project Management Fundamentals
  2. Project Life Cycle
  3. Project Initiation
  4. Project Planning
  5. Project Execution
  6. Project Monitoring and Controlling
  7. Project Closing
  8. Project Scope Management
  9. Project Schedule Management
  10. Project Cost Management
  11. Project Quality Management
  12. Project Resource Management
  13. Project Communication Management
  14. Project Risk Management
  15. Project Procurement Management
  16. Project Stakeholder Management
  17. Project Governance
  18. Project Management Methodologies
  19. Project Management Tools and Techniques
  20. Project Leadership and Team Management
  21. Project Success Criteria and Metrics
  22. Project Documentation and Reporting
  23. Project Change Management
  24. Project Integration Management

Managing Security Awareness

6 concepts · 48 questions
  1. Security Awareness Program Fundamentals
  2. Security Awareness Training Delivery
  3. Measuring Security Awareness Effectiveness
  4. Phishing Simulations and Social Engineering Tests
  5. Incident Reporting and Response in Awareness Context
  6. Continuous Improvement of Awareness Programs

Networking Concepts for Managers

10 concepts · 50 questions
  1. Network Fundamentals
  2. Network Topologies
  3. OSI and TCP/IP Models
  4. IP Addressing and Subnetting
  5. Network Protocols
  6. Network Devices
  7. LAN, WAN, and MAN
  8. Wireless Networking
  9. Network Security Basics
  10. Network Management and Monitoring

Network Security Architecture

8 concepts · 50 questions
  1. Network Security Architecture Fundamentals
  2. Network Segmentation and Zoning
  3. Secure Network Design Patterns
  4. Network Access Control (NAC)
  5. Firewall and IDS/IPS Architecture
  6. VPN and Remote Access Security
  7. Network Monitoring and Logging
  8. Resilience and Redundancy in Network Architecture
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GSLC, so none is invented.