Gslc Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 224 questions. Use the simulator for timed and flashcard mode.

Try Simulator

GSLC-2020 Sample Questions

  1. Question 1

    Q1

    A global logistics company is developing its first formal information security program. The CISO has a limited budget and needs to demonstrate early value to the board. Which of the following approaches represents the most effective initial step in establishing a risk management framework?

    Show answer & explanation

    Correct answer: C

    For a new program with a limited budget, a high-level qualitative risk assessment is the most effective starting point. It allows the CISO to quickly identify and prioritize the most significant risks to critical business functions without the time and resource-intensive nature of a full quantitative analysis or a GRC tool implementation. This approach provides immediate, actionable insights to demonstrate value and guide initial security investments.

  2. Question 2

    Q2Multiple answers

    A healthcare provider recently suffered a data breach originating from a third-party billing service. The security manager is now tasked with strengthening the vendor management program. Which TWO of the following controls are most critical to implement to prevent a recurrence? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Conducting regular, rigorous security audits (on-site or via documentation review) provides direct evidence of a vendor's security posture and control effectiveness.

    Strong contractual language is fundamental. It legally obligates the vendor to meet specific security standards, report incidents promptly, and allow the organization to verify compliance through audits.

  3. Question 3

    Q3

    A security manager is briefing the executive team on the phases of incident response. They want to explain the primary goal of the 'Containment' phase in a way that resonates with business leaders. What is the most accurate and business-focused description of this phase?

    Show answer & explanation

    Correct answer: B

    The core purpose of the Containment phase is to limit the scope and magnitude of the incident. From a business perspective, this means stopping the financial, reputational, and operational bleeding. This description is accurate, concise, and directly relates the technical action to its business impact.

  4. Question 4

    Q4

    True or False: A security 'standard' is a high-level, principle-based document that establishes an organization's security intent and goals, while a 'policy' provides mandatory, specific configurations or rules to enforce those standards.

    Show answer & explanation

    Correct answer: B

    This statement has the definitions reversed. A 'policy' is the high-level document outlining goals and intent. A 'standard' is a mandatory document that specifies the technologies, configurations, and rules that must be implemented to comply with the policy.

  5. Question 5

    Q5

    A fast-growing e-commerce company is struggling with its vulnerability management program. The security team performs monthly scans, but the development teams are overwhelmed by the volume of findings and are slow to patch. As the security manager, what is the most critical process improvement to implement first?

    Show answer & explanation

    Correct answer: B

    The core problem is not the lack of findings, but the inability to act on them. A risk-based prioritization model is the most crucial first step. It allows the team to focus developers' limited time on the vulnerabilities that pose the greatest actual risk to the business, rather than treating all findings equally. This makes the remediation workload manageable and demonstrably reduces risk.

  6. Question 6

    Q6

    Case Study

    A mid-sized financial services firm, FinSecure, has recently decided to migrate a significant portion of its on-premises infrastructure to a public cloud provider. The CISO, reporting to the CIO, has been tasked with leading this initiative from a security perspective. The company culture is highly risk-averse, and the board is concerned about meeting stringent regulatory compliance requirements (like PCI DSS and GDPR) in the cloud. The project team is composed of traditional network and system administrators who have limited cloud experience.

    The CISO's primary objective is to build a secure and compliant cloud environment without stifling the agility benefits the company hopes to gain. The initial project plan from the IT team focuses heavily on a 'lift-and-shift' migration of existing virtual machines and security appliances. The CISO is concerned this approach will not adequately address cloud-native security challenges and may be more costly in the long run.

    What is the most effective strategy the CISO should advocate for to ensure the long-term security and success of the cloud migration project?

    Show answer & explanation

    Correct answer: C

    This strategy addresses the root causes of the problem: lack of cloud experience, a flawed migration plan, and compliance concerns. Establishing a CCoE builds internal expertise. Developing a framework based on the Shared Responsibility Model clarifies security roles. Prioritizing re-architecture with cloud-native controls is more secure, scalable, and cost-effective than a simple 'lift-and-shift' of legacy security models. This demonstrates strategic leadership that balances security, compliance, and business agility.

  7. Question 7

    Q7

    A SOC manager is evaluating technologies to reduce analyst fatigue and improve response times. They are considering a SOAR (Security Orchestration, Automation, and Response) platform. What is the primary function of a SOAR platform in a SOC environment?

    Show answer & explanation

    Correct answer: C

    The core value of a SOAR platform is automation and orchestration. It integrates with other security tools (like SIEM, EDR, firewalls) and uses predefined 'playbooks' to automate sequences of actions, such as enriching alerts, quarantining hosts, or blocking IP addresses. This frees up analysts from repetitive tasks to focus on more complex investigations.

  8. Question 8

    Q8

    As part of integrating security into a mature CI/CD pipeline, a security architect recommends several testing methodologies. Which approach uses instrumentation within a running application during dynamic testing to identify vulnerabilities in real-time?

    Show answer & explanation

    Correct answer: D

    IAST is the methodology that combines elements of both SAST and DAST. It works by deploying an agent that instruments the application code. As automated or manual dynamic tests are performed, the IAST agent observes the application's behavior from the inside, allowing it to pinpoint the exact line of code responsible for a vulnerability with high accuracy.

  9. Question 9

    Q9

    A security manager is defining endpoint protection requirements for a company with a large remote workforce. The primary concerns are zero-day threats and fileless malware. Which technology is most essential for addressing these specific threats?

    Show answer & explanation

    Correct answer: C

    Traditional AV is ineffective against zero-day and fileless attacks because they lack known signatures. EDR solutions excel here by focusing on behavioral analysis. They monitor system processes, memory, and network connections for anomalous activities (TTPs - Tactics, Techniques, and Procedures) indicative of an attack, regardless of whether a malicious file is present. This makes EDR critical for detecting modern, sophisticated threats.

  10. Question 10

    Q10

    A company's Acceptable Use Policy (AUP) is outdated and widely ignored by employees. The security manager needs to revitalize the policy framework. Which of the following is the most important factor for creating an effective and enforceable AUP?

    Show answer & explanation

    Correct answer: B

    A policy without executive sponsorship and clear communication is merely a suggestion. For an AUP to be effective, it must have visible support from leadership, be clearly and regularly communicated to all employees in understandable language, and have well-defined, consistently applied consequences for violations. This creates a culture of accountability and ensures the policy is taken seriously.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the GSLC-2020 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 224 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon