
GIAC Security Leadership
Domain 4Objective 1
Cryptography Concepts for Managers GSLC Practice Questions (Page 10)
Part of the Cryptography and Privacy domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 46–50
- 46
A security manager discovers that a malicious actor has been intercepting encrypted communications and has collected a large amount of ciphertext. The actor is now using a technique that exploits the fact that two different inputs can produce the same hash output. Which attack is the actor attempting?
Select an answer first - 47
How does a hash function provide data integrity?
Select an answer first - 48
A financial institution must comply with a regulation that requires customer data to be encrypted both at rest and in transit. The compliance team asks the security manager to provide evidence of encryption controls. What is the most appropriate response?
Select an answer first - 49
A security analyst notices that an attacker has been capturing encrypted network traffic for months and is now using a large amount of computing power to try to guess the encryption key. Which type of attack is this?
Select an answer first - 50
Which regulatory requirement is directly supported by using digital signatures to ensure the authenticity and integrity of electronic records?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.