
GIAC Security Leadership
Domain 5Objective 3
Managing Security Awareness GSLC Practice Questions (Page 5)
Part of the Business and Vendor Management domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 21–25
- 21
A security team is planning its first phishing simulation. The goal is to measure the organization's baseline susceptibility without causing undue disruption. Which approach best achieves this goal?
Select an answer first - 22
An organization has a mature security awareness program, but the incident reporting rate is low. Employees say they are unsure what constitutes a reportable incident. Which change would most effectively improve the reporting rate?
Select an answer first - 23
What is the primary goal of conducting a phishing simulation?
Select an answer first - 24
A company has run phishing simulations for six months. The overall click rate has dropped from 20% to 12%, but the click rate in the finance department remains at 25%. The security manager wants to improve the program. What should the manager do first?
Select an answer first - 25
A security manager is evaluating the effectiveness of the security awareness program. The program includes annual training, quarterly phishing simulations, and a reporting mechanism. Which metric would provide the most balanced view of the program's impact on employee behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.