
GIAC Security Leadership
Domain 5Objective 1
Managing Negotiations and Vendors GSLC Practice Questions (Page 5)
Part of the Business and Vendor Management domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 21–25
- 21
A security team has signed a contract with a new managed detection and response (MDR) vendor. The vendor is responsible for 24/7 monitoring and alerting. The team wants to ensure the vendor meets its performance commitments and maintains a good working relationship. Which ongoing practice is MOST effective for managing this vendor relationship?
Select an answer first - 22
A security manager is negotiating a contract with a security vendor that will process sensitive customer data. The vendor's standard contract includes a clause that limits liability to the amount paid under the contract. The manager is concerned about the potential financial impact of a data breach. The vendor is unwilling to remove the liability cap entirely. Which negotiation approach is MOST likely to achieve a reasonable outcome?
Select an answer first - 23
A security manager is finalizing a contract with a cloud security vendor. The vendor's standard terms include a limitation of liability clause that caps damages at the total contract value. The manager is concerned about a potential data breach that could cause significant financial and reputational damage. Which contract term should the manager negotiate to address this concern?
Select an answer first - 24
Which statement best describes the role of negotiation in vendor management?
Select an answer first - 25
A company is selecting a vendor for a new security information and event management (SIEM) platform. The security team has defined requirements, but the procurement department insists on choosing the lowest-priced vendor. The security team has identified that the lowest-priced vendor lacks critical integration capabilities. What should the security manager do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.