
GIAC Security Leadership
Domain 1Objective 3
Risk Management and Security Frameworks GSLC Practice Questions (Page 9)
Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 41–44
- 41
What is the first step in applying a security framework to an organization?
Select an answer first - 42
Which security framework is best known for providing a comprehensive set of cybersecurity controls and is widely used as a baseline for security programs?
Select an answer first - 43
What is the primary purpose of risk communication in the risk management process?
Select an answer first - 44
After a risk assessment, a healthcare organization's CISO needs to report the top risks to the board of directors. The board is not technical and is primarily concerned with financial impact and regulatory exposure. What is the most effective way to communicate the risk findings?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GSLC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.