Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 2Objective 1

Managing System Security GSLC Practice Questions (Page 6)

Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 26–30

  1. 26application · medium

    During a routine security review, an administrator discovers that a server was compromised three weeks ago. The attacker may have exfiltrated sensitive data. The server is still running and connected to the network. What is the most appropriate first step in the incident response process?

    Select an answer first
  2. 27expert · hard

    A company has just experienced a data breach where customer credit card information was stolen. The breach was discovered by an external security researcher who notified the company. The company's incident response plan is outdated and does not cover this scenario. What is the most important immediate action?

    Select an answer first
  3. 28application · medium

    A security manager is reviewing the monitoring strategy for a financial services company. The company must detect unauthorized changes to critical configuration files on its payment processing servers and retain audit logs for at least one year to meet regulatory requirements. The current solution only collects authentication logs. Which additional control is most directly needed to meet both requirements?

    Select an answer first
  4. 29application · medium

    A financial services firm is deploying 200 new Windows workstations for employees who handle customer data. The security team wants to ensure consistent security configurations across all devices and reduce the risk of misconfiguration. Which approach best meets this requirement?

    Select an answer first
  5. 30application · medium

    A healthcare organization is implementing a new electronic health record (EHR) system. The system must allow nurses to view patient records and add notes, but only physicians can modify diagnoses. The organization must also ensure that access is revoked promptly when a staff member leaves. Which access control model best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.