
GIAC Security Leadership
Domain 3Objective 4
Vulnerability Management GSLC Practice Questions (Page 1)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 1–5
- 1
How does vulnerability management primarily help reduce the likelihood of security incidents?
Select an answer first - 2
A security manager is responsible for vulnerability management in a healthcare organization. A vulnerability scan identified a critical vulnerability in a medical device that is used in patient care. The device cannot be patched because the vendor has not released a patch, and the device is required for patient monitoring. The device is connected to the hospital network, but it is isolated in a separate VLAN. The organization has a policy that requires all critical vulnerabilities to be remediated within 30 days. The vulnerability has been open for 45 days. What should the security manager do?
Select an answer first - 3
A security analyst at a regional bank has completed a quarterly vulnerability scan. The scan identified a critical-severity SQL injection flaw in an internet-facing customer portal, a high-severity flaw in an internal HR application that requires authentication, and a medium-severity flaw in a legacy file server that is isolated from the network. The bank's risk appetite is low, but the patching team has limited capacity this week. Which remediation priority should the analyst recommend?
Select an answer first - 4
A vulnerability management team has completed a remediation cycle for a set of critical vulnerabilities. The team lead needs to report to the CISO, who is concerned about the organization's risk posture. The CISO wants to know which vulnerabilities are still open and what the residual risk is. The team has already patched 80% of the critical vulnerabilities. The remaining 20% are on systems that cannot be patched because they are legacy. The team has implemented compensating controls for those systems. What should the team report to the CISO?
Select an answer first - 5
A security analyst is building a vulnerability management program for a mid-sized company. The analyst wants to ensure that newly disclosed vulnerabilities are identified as soon as they are publicly known. Which combination of sources should the analyst use to stay informed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.