Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 3Objective 4

Vulnerability Management GSLC Practice Questions (Page 2)

Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 6–10

  1. 6foundation · easy

    Which sequence correctly represents the typical phases of the vulnerability management lifecycle?

    Select an answer first
  2. 7application · medium

    A vulnerability scan identified a remote code execution vulnerability in a web application that is exposed to the internet. The same vulnerability also exists on an internal development server that is not accessible from the internet. The web application is a critical business system, while the development server is used by a small team. Which vulnerability should be remediated first?

    Select an answer first
  3. 8application · medium

    A security analyst is reviewing a vulnerability scan report. The report shows a vulnerability with a CVSS score of 9.8 on a server that hosts a public-facing marketing website. The same vulnerability also appears on an internal file server with a CVSS score of 9.8. The marketing website is not critical to business operations, while the file server contains sensitive employee data. Which vulnerability should be remediated first?

    Select an answer first
  4. 9application · medium

    A company has just experienced a security incident where an attacker exploited a known vulnerability in a public-facing web server. The vulnerability had been identified in a scan three months ago but was not remediated. The incident response team has contained the breach. What should the vulnerability management team do next to prevent a recurrence?

    Select an answer first
  5. 10expert · hard

    A financial services firm discovers a critical vulnerability in a third-party application that processes customer transactions. The vendor has released a patch, but the patch is known to cause intermittent downtime during business hours. The firm cannot afford downtime during peak transaction hours. Which remediation approach best balances security and business continuity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.