Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 3Objective 4

Vulnerability Management GSLC Practice Questions (Page 7)

Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 31–35

  1. 31application · medium

    During an incident response investigation, the team discovers that the attacker exploited a vulnerability that was known but not patched. The vulnerability had been identified in a scan six months ago. The incident response team wants to prevent similar incidents. What should the vulnerability management team do?

    Select an answer first
  2. 32application · medium

    After a major patching effort, the vulnerability management team wants to confirm that all critical vulnerabilities have been resolved. The team has already applied patches and configuration changes. What is the best way to verify the remediation?

    Select an answer first
  3. 33expert · hard

    A security manager at a university must prioritize vulnerabilities across research systems that handle grant data and administrative systems that handle student records. Both are internet-facing. The research systems have a critical vulnerability with no known exploit, while the administrative systems have a high vulnerability that is actively being exploited in the wild. Which should be prioritized?

    Select an answer first
  4. 34application · medium

    During an incident response investigation, the team discovers that the attacker exploited a known vulnerability that had been identified in a vulnerability scan three months earlier but had not been patched. Which improvement to the vulnerability management program would most directly reduce the likelihood of a similar incident?

    Select an answer first
  5. 35application · medium

    A security analyst is reviewing a vulnerability scan report and notices a critical vulnerability in a software product that the company uses. The analyst wants to confirm the vulnerability details and check whether any vendor mitigation is available. Which source should the analyst consult first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.