Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 2Objective 1

Managing System Security GSLC Practice Questions (Page 5)

Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 21–25

  1. 21expert · hard

    A hospital's IT department manages a mix of Windows servers, Linux servers, and medical devices. A critical vulnerability has been announced for a third-party application used on some Windows servers. The vendor has released a patch, but the hospital's change advisory board (CAB) requires that all patches be tested for at least two weeks before deployment to avoid disrupting patient care. However, the vulnerability is being actively exploited in the wild. The security team must decide how to proceed. What is the best course of action?

    Select an answer first
  2. 22application · medium

    A regional bank must patch a critical remote-code-execution vulnerability in its internet-facing web application server. The vulnerability was disclosed 48 hours ago, and exploit code is already circulating. The bank's change advisory board (CAB) normally requires a 2-week testing cycle for all production changes, and the application team wants to run the full regression suite before deploying. The bank's compliance team has confirmed that the current control environment is adequate for a temporary exception. What is the most appropriate action for the security manager to take?

    Select an answer first
  3. 23expert · hard

    A company is planning to replace its legacy on-premises email system with a cloud-based email service. The security team must ensure a secure migration. What is the most important security consideration during the migration?

    Select an answer first
  4. 24application · medium

    A company's security policy requires that all changes to critical servers be logged and that the logs be retained for at least one year for compliance. The system administrator notices that logs are being overwritten after only 30 days. What should the administrator do to meet the policy?

    Select an answer first
  5. 25expert · hard

    A manufacturing company is purchasing new industrial control system (ICS) equipment for a production line. The equipment will be connected to the corporate network for monitoring and maintenance. The security team is concerned about the security of the new equipment. What is the most important security consideration during the procurement phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.