
GIAC Security Leadership
Domain 1Objective 3
Risk Management and Security Frameworks GSLC Practice Questions (Page 2)
Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 6–10
- 6
A multinational corporation is subject to the General Data Protection Regulation (GDPR) and needs to demonstrate that it has appropriate technical and organizational measures to protect personal data. The company has implemented a comprehensive risk management program. What is the PRIMARY way this program supports GDPR compliance?
Select an answer first - 7
A healthcare organization is subject to HIPAA and must demonstrate compliance with its security rule. The organization has implemented a risk management program but has not formally adopted a security framework. The compliance officer wants to use a framework to help organize and demonstrate compliance. Which framework is MOST appropriate for this purpose?
Select an answer first - 8
A large enterprise has a diverse portfolio of risks, including legacy systems with known vulnerabilities, new cloud deployments, and third-party vendor risks. The risk team has limited resources and must prioritize which risks to assess in detail. What is the most effective prioritization strategy?
Select an answer first - 9
A retail company is considering implementing the NIST Cybersecurity Framework (CSF). The company has a mature security program but wants to improve communication about cybersecurity risk with its board of directors. Which aspect of the NIST CSF would be MOST helpful for this goal?
Select an answer first - 10
A regional bank is conducting its annual risk assessment. The CISO asks the security team to identify assets, threats, and vulnerabilities, then determine the likelihood and impact of potential events. The team has completed the identification and analysis phases. What is the next step in the risk assessment process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.