Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 1Objective 3

Risk Management and Security Frameworks GSLC Practice Questions (Page 1)

Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    What is the primary purpose of the NIST Cybersecurity Framework (CSF)?

    Select an answer first
  2. 2expert · hard

    A large enterprise has implemented a risk management program and identified a high-risk vulnerability in a legacy system that cannot be patched. The system is critical to operations. The CISO must communicate this risk to the executive team, who are focused on cost and operational continuity. The CISO has decided to accept the risk but wants to ensure ongoing monitoring. What is the MOST appropriate way to communicate and monitor this risk?

    Select an answer first
  3. 3expert · hard

    A government agency has implemented a risk management program and identified a high-risk vulnerability in a public-facing web application. The agency has a low risk tolerance and must report to a congressional oversight committee. The CISO needs to communicate the risk and the agency's response to the committee, which is not technically sophisticated. What is the MOST effective way to communicate this risk?

    Select an answer first
  4. 4application · medium

    A mid-sized e-commerce company wants to improve its security posture but has limited staff and budget. The company is not required to comply with a specific security standard but wants a practical, prioritized list of actions to implement. Which framework would be the most suitable?

    Select an answer first
  5. 5application · medium

    During a risk assessment for a hospital's patient portal, the team identifies that the portal is vulnerable to a denial-of-service attack that could prevent patients from accessing their medical records. The team determines that the likelihood is low because the portal is behind a DDoS protection service, but the impact is high because patients rely on the portal for critical services. According to the risk assessment process, what should the team do after scoring the risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.