
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 11)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 51–55
- 51
A web application allows users to upload profile pictures. An attacker uploads a file containing malicious script that executes when other users view the profile. Which type of vulnerability is this?
Select an answer first - 52
A company is migrating a monolithic application to a microservices architecture using containers. The security manager must balance the need for rapid deployment with the need to prevent known vulnerabilities from reaching production. Which strategy best achieves this balance?
Select an answer first - 53
What is the first step in the vulnerability management process for applications?
Select an answer first - 54
What is the primary impact of a cross-site scripting (XSS) vulnerability?
Select an answer first - 55
Which of the following is an example of an injection vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.