
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 7)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 31–35
- 31
Which application security control is specifically designed to prevent malicious input from being processed by the application?
Select an answer first - 32
A healthcare startup is building a patient portal that will handle PHI. The security manager is leading the design phase and wants to identify potential threats before any code is written. The team has limited time and needs a structured approach that focuses on data flows and trust boundaries. Which approach best meets this need?
Select an answer first - 33
Which secure coding practice is most effective at preventing SQL injection vulnerabilities?
Select an answer first - 34
A security manager is responsible for testing a web application that has both a JavaScript-heavy frontend and a complex backend API. The team wants to identify vulnerabilities that are only visible when the application is running, such as business logic flaws and authentication bypasses. Which testing approach is most appropriate?
Select an answer first - 35
What is the primary purpose of application security metrics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.