
GIAC Security Leadership
Domain 1Objective 3
Risk Management and Security Frameworks GSLC Practice Questions (Page 4)
Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 16–20
- 16
A manufacturing company has completed a risk assessment and identified that its legacy industrial control systems (ICS) have unpatched vulnerabilities. The CISO needs to communicate this risk to the plant operations manager, who is not technically savvy. What is the MOST effective way to communicate this risk?
Select an answer first - 17
A multinational corporation operates in multiple countries with varying data protection laws. The company wants to adopt a single security framework that can be applied consistently across all subsidiaries while satisfying local regulatory requirements. Which approach is the most effective?
Select an answer first - 18
A public utility company is subject to a new regulation that requires it to demonstrate a formal, documented process for identifying and managing cybersecurity risks. The company already has a risk register and conducts annual risk assessments. What is the MOST important additional step to satisfy the regulation?
Select an answer first - 19
A company has identified a high-risk vulnerability in its customer database that could lead to a major data breach. The cost to fix the vulnerability is significant, and the company is considering accepting the risk because the likelihood of exploitation is low. However, the regulatory environment is strict, and a breach would result in heavy fines. What is the most appropriate decision?
Select an answer first - 20
A software development company is conducting a risk assessment for a new customer-facing application. The team has identified that the application stores sensitive customer data and that a data breach could result in regulatory fines and reputational damage. They have analyzed the likelihood and impact and determined the risk level. What should the team do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.