Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 4Objective 1

Cryptography Concepts for Managers GSLC Practice Questions (Page 7)

Part of the Cryptography and Privacy domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts

Questions 31–35

  1. 31application · medium

    A security analyst notices that an attacker has been capturing encrypted traffic between a web server and clients. The analyst suspects the attacker is trying to build a massive table of possible keys to eventually decrypt the traffic. Which cryptographic attack is the analyst observing?

    Select an answer first
  2. 32expert · hard

    A security team discovers that an attacker has been intercepting encrypted communications and performing a downgrade attack, forcing the client and server to use a weaker encryption algorithm. The team wants to prevent this attack. Which control is most effective?

    Select an answer first
  3. 33expert · hard

    A startup is building a messaging application that must provide end-to-end encryption. The team is deciding between using only symmetric encryption with pre-shared keys or using asymmetric encryption for key exchange. The application must scale to millions of users, and users may join without prior coordination. Which approach is more appropriate, and what is the primary reason?

    Select an answer first
  4. 34foundation · easy

    Which aspect of key management involves securely transferring a cryptographic key from the key generation system to the systems that will use it?

    Select an answer first
  5. 35expert · hard

    A multinational company must comply with data protection regulations that require personal data to be encrypted. The company operates in multiple regions, and some regulations require data to remain within specific geographic boundaries. The security manager must design a solution that satisfies both encryption and data residency requirements. What is the most appropriate approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.