
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 1)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 1–5
- 1
What is a common tool or technique used to manage risks from open source components?
Select an answer first - 2
A company is adopting infrastructure as code (IaC) to manage its cloud environment. The security manager wants to ensure that security is integrated into the IaC pipeline. Which practice is most effective?
Select an answer first - 3
Which security design principle ensures that a user or process is granted only the minimum permissions necessary to perform its function?
Select an answer first - 4
A DevOps team deploys containerized microservices to a cloud platform. The security manager wants to ensure that security checks are integrated into the continuous integration/continuous deployment (CI/CD) pipeline. Which action best achieves this?
Select an answer first - 5
Why is it important to verify that a vulnerability has been remediated?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.