
GIAC Security Leadership
Domain 1Objective 3
Risk Management and Security Frameworks GSLC Practice Questions (Page 5)
Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 21–25
- 21
A financial services firm must comply with strict regulatory requirements for data protection and wants to demonstrate a robust security program to auditors. The firm already has strong technical controls but lacks a formal, risk-based approach to managing security. Which framework would be most appropriate to adopt?
Select an answer first - 22
What is the primary purpose of risk management in an organizational security program?
Select an answer first - 23
A company has decided to implement ISO/IEC 27001. The implementation team is struggling with the scope of the ISMS and the level of documentation required. The company wants to achieve certification within a year. What is the most effective approach to manage this project?
Select an answer first - 24
How does risk management support governance in an organization?
Select an answer first - 25
A government contractor must comply with a federal regulation that requires a risk management framework specifically designed for federal information systems. Which framework should the contractor implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.