
GIAC Security Leadership
Domain 4Objective 1
Cryptography Concepts for Managers GSLC Practice Questions (Page 3)
Part of the Cryptography and Privacy domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 11–15
- 11
Which component of a PKI is responsible for verifying the identity of an entity before a certificate is issued?
Select an answer first - 12
A security manager is reviewing the organization's cryptographic controls and discovers that a legacy system uses a weak encryption algorithm. The system is critical and cannot be taken offline easily. What should the manager do first?
Select an answer first - 13
Which cryptographic attack involves an attacker intercepting and altering communications between two parties without their knowledge?
Select an answer first - 14
A company's encryption keys are managed by a third-party cloud KMS. The security manager is concerned about the risk of the KMS provider suffering a data breach that exposes keys. What is the best way to mitigate this risk?
Select an answer first - 15
A security manager must decide between using a hardware security module (HSM) or a software-based key management system for storing the organization's encryption keys. The organization has a high volume of cryptographic operations and requires low latency. The budget is limited. Which factor is most important in this decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.