
GIAC Security Leadership
Domain 3Objective 4
Vulnerability Management GSLC Practice Questions (Page 9)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 41–45
- 41
A vulnerability scan of a network segment reports a large number of false positives. The security analyst needs to improve the accuracy of the scan results before prioritizing remediation. Which action would most effectively reduce false positives?
Select an answer first - 42
When reporting vulnerability status to stakeholders, what is a key characteristic of an effective report?
Select an answer first - 43
A vulnerability management team has completed a remediation cycle. The team needs to report to the board of directors. The board is not technical and wants a high-level summary of the organization's risk posture. Which reporting approach is most appropriate?
Select an answer first - 44
Which of the following is an example of a vendor advisory that provides vulnerability information?
Select an answer first - 45
A company discovers a critical vulnerability in a legacy application that is no longer supported by the vendor. The application is essential to business operations and cannot be replaced in the short term. Which remediation strategy is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.