
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 8)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 36–40
- 36
A DevOps team is building a CI/CD pipeline for a containerized microservices application. The security manager wants to integrate security testing into the pipeline without slowing down deployments. Which approach best balances security and speed?
Select an answer first - 37
What is the purpose of incorporating defense in depth into application design?
Select an answer first - 38
What is the primary purpose of application security within an organization's overall security management program?
Select an answer first - 39
A security manager wants to measure the effectiveness of the application security program and report to executives. The executives are interested in understanding the return on investment and whether the program is reducing risk. Which metric would be most meaningful for this audience?
Select an answer first - 40
A security manager discovers that a widely used open source library has a critical vulnerability. The library is used in multiple applications, but the vendor has not yet released a patch. The security manager needs to decide how to respond. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.