Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 3Objective 4

Vulnerability Management GSLC Practice Questions (Page 4)

Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 16–20

  1. 16foundation · easy

    Which of the following is a primary source for publicly disclosed vulnerability information?

    Select an answer first
  2. 17foundation · easy

    Which of the following is a valid remediation strategy for a vulnerability?

    Select an answer first
  3. 18application · medium

    A security operations center (SOC) has observed an increase in attempts to exploit a specific vulnerability in a widely used software product. The vulnerability is not yet patched in the organization. The incident response team has been alerted. What is the most effective way to integrate vulnerability management with incident response in this situation?

    Select an answer first
  4. 19expert · hard

    A large organization has a vulnerability management program that scans all assets monthly. The latest scan identified a critical remote code execution vulnerability in a legacy application that is used by the research department. The application is not internet-facing, but it is connected to the corporate network. The vendor has released a patch, but the patch requires a reboot of the application server, which would cause downtime for the research team. The research team is in the middle of a critical project and cannot afford downtime. The organization has a compensating control in place: the application is behind a firewall that only allows access from the research department's subnet. The threat intelligence team reports that the vulnerability is being actively exploited in the wild, but only against internet-facing systems. What should the security manager recommend?

    Select an answer first
  5. 20application · medium

    A vulnerability management analyst has patched a critical vulnerability on a server. Before closing the ticket, the analyst must verify that the patch was effective. Which action provides the most reliable verification?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.