
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 5)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 21–25
- 21
In a DevOps pipeline, at which stage should security testing be integrated to be most effective?
Select an answer first - 22
A security architect is leading a threat modeling exercise for a new online payment system. The system will handle credit card data and must comply with PCI DSS. The team has identified several threats, but they have limited time to address all of them. Which approach should the architect use to prioritize the threats?
Select an answer first - 23
Which of the following is an example of an application security governance activity?
Select an answer first - 24
A security architect is designing a public-facing web application that will accept file uploads from users. The application will store these files and serve them back to other users. Which set of controls is most effective in preventing malicious file uploads from compromising the server?
Select an answer first - 25
An application was breached through a vulnerability in a third-party component. The incident response team has contained the breach and restored service. The security manager must decide how to prevent similar incidents in the future. Which action is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.