Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 3Objective 4

Vulnerability Management GSLC Practice Questions (Page 5)

Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 21–25

  1. 21foundation · easy

    When interpreting vulnerability scan results, what does a 'false positive' mean?

    Select an answer first
  2. 22application · medium

    A critical vulnerability has been identified in a third-party application that is used by the HR department. The vendor has released a patch, but the patch is known to cause compatibility issues with the company's single sign-on (SSO) system. The HR application is essential for payroll processing. What should the security team do?

    Select an answer first
  3. 23expert · hard

    A manufacturing company has a legacy SCADA system that controls a critical production line. A vulnerability scan found a remotely exploitable flaw in the system's web interface. The vendor has not released a patch and will not provide one for at least six months. The system cannot be taken offline during production hours, and the company has a low risk tolerance. Which remediation strategy best balances risk reduction with operational continuity?

    Select an answer first
  4. 24application · medium

    An incident response team is handling a ransomware event that exploited a known vulnerability in an internet-facing application. The vulnerability had been identified in a scan but was not remediated because it was assigned a medium severity. After the incident, the security manager wants to prevent similar events. Which change to the vulnerability management program would be most effective?

    Select an answer first
  5. 25expert · hard

    A vulnerability management team is reviewing the results of a quarterly scan. The scan identified a critical vulnerability in a database server that stores customer payment information. The database is not directly accessible from the internet, but it is accessible from the internal network. The team has a limited patching window and must decide which vulnerabilities to remediate first. The scan also identified a high-severity vulnerability in a public-facing web server that is not critical to business operations. The threat intelligence team reports that the database vulnerability is not being exploited in the wild, while the web server vulnerability is being actively exploited. What should the team do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.