
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 2)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 6–10
- 6
Which of the following is an example of an application security metric?
Select an answer first - 7
A project manager wants to ensure that security is considered throughout the development lifecycle of a new application, not just at the end. Which approach should be adopted?
Select an answer first - 8
A security manager needs to report to the board on the effectiveness of the application security program. Which metric would provide the most meaningful insight into whether the program is reducing risk over time?
Select an answer first - 9
An organization's web application was compromised through a SQL injection vulnerability. The incident response team has contained the immediate threat. What is the next most important step in the recovery process?
Select an answer first - 10
A software company uses many open source libraries in its products. A new critical vulnerability is announced in one of these libraries. The security manager needs to determine which products are affected and prioritize remediation. What is the first step the security manager should take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.