
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 10)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 46–50
- 46
Why is it important to assess the security of third-party and open source components used in applications?
Select an answer first - 47
Which structured threat modeling methodology uses a diagram of data flows, trust boundaries, and threat categories such as STRIDE?
Select an answer first - 48
A large organization has multiple development teams using different security practices. The security manager wants to standardize application security across the organization. Which action is most effective?
Select an answer first - 49
Which of the following best describes how security is integrated into the design phase of a Secure Software Development Lifecycle?
Select an answer first - 50
A large organization has multiple development teams using different frameworks and coding standards. The security manager wants to establish consistent application security governance across the organization. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.