
GIAC Security Leadership
Domain 5Objective 3
Managing Security Awareness GSLC Practice Questions (Page 7)
Part of the Business and Vendor Management domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 31–35
- 31
An employee receives an email that looks like it is from the CEO asking for a wire transfer. The employee suspects phishing but is not sure. The company's security awareness program emphasizes incident reporting. What should the employee do?
Select an answer first - 32
How does a security awareness program contribute to incident response?
Select an answer first - 33
An employee receives a suspicious email and reports it to the security team. The security team investigates and confirms it is a phishing attempt. What should the security team do next to reinforce the value of reporting?
Select an answer first - 34
After a year of security awareness training, the security team wants to evaluate whether the program has reduced risky behavior. Which metric would provide the most direct evidence of behavior change?
Select an answer first - 35
After a phishing simulation, the security team notices that many employees who clicked the simulated phishing email did not report it. The team wants to improve the reporting rate. Which metric should they focus on and what action should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.