
GIAC Security Leadership
Domain 2Objective 4
Managing Application Security GSLC Practice Questions (Page 9)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
15concepts
Questions 41–45
- 41
Which of the following is a secure coding practice to prevent cross-site scripting (XSS)?
Select an answer first - 42
What is a key security consideration when using containers in a cloud environment?
Select an answer first - 43
A company has a large development team with varying levels of security knowledge. The security manager wants to improve the team's ability to write secure code. Which approach is most effective in the long term?
Select an answer first - 44
A company is migrating a legacy monolithic application to a containerized microservices architecture in the cloud. The security manager must ensure that security testing is integrated into the new CI/CD pipeline. The team uses many open source libraries and wants to avoid slowing down the pipeline. Which approach best addresses these concerns?
Select an answer first - 45
A web application accepts user input in a search field and displays the results on the same page. A security review identified that the application is vulnerable to reflected cross-site scripting (XSS). Which control should be implemented to mitigate this vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.