
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 4)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 16–20
- 16
A financial services company is developing a customer-facing web application that accepts loan applications. The application allows users to upload documents and submit personal information. The security team wants to prevent injection attacks and cross-site scripting. Which combination of controls should be implemented?
Select an answer first - 17
A company is developing a new internal tool that will handle sensitive customer data. The security manager is defining security requirements during the design phase. Which requirement best reflects the principle of least privilege?
Select an answer first - 18
Which of the following is an effective way to promote application security awareness among stakeholders?
Select an answer first - 19
A security team has identified a critical vulnerability in a third-party component used by several applications. The vulnerability is actively being exploited in the wild. The team has limited resources and cannot patch all applications immediately. What should the team do first?
Select an answer first - 20
A web application is suspected of being compromised through a SQL injection vulnerability. The security team needs to contain the incident and prevent further damage. Which action should be taken first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.