
GIAC Security Leadership
Domain 3Objective 4
Vulnerability Management GSLC Practice Questions (Page 3)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 11–15
- 11
A vulnerability management team has remediated a set of critical vulnerabilities across the environment. The team lead must report the status to the CISO. The CISO wants to know which vulnerabilities are truly fixed and which remain open. The team has already applied patches and configuration changes. What should the team do before reporting to the CISO?
Select an answer first - 12
After a critical vulnerability was patched across 200 servers, the vulnerability management lead must report status to the CISO. The lead wants to confirm that the patch was actually applied and that no server remains vulnerable. Which action should the lead take to verify remediation effectiveness?
Select an answer first - 13
What is the primary purpose of verifying remediation efforts?
Select an answer first - 14
A security analyst is reviewing a vulnerability scan report and sees a critical vulnerability on a server that is scheduled for decommissioning in two weeks. The server is not accessible from the internet and contains no sensitive data. What should the analyst do?
Select an answer first - 15
How does vulnerability management support incident response during an active security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.