10 exam-style questions with answers and explanations, straight from our 1,036-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free GSLC questions are organized by exam domain, so you can see how each part of the GIAC Security Leadership blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Cryptography Concepts for Managers
Question 1
During a policy review, a manager notes that one document recommends-but does not require-that staff enable a password manager. Within the security documentation hierarchy, this document is BEST classified as a:
Show answer & explanation
Correct answer: C - Guideline, because it is advisory rather than mandatory
Question 2
An asset is valued at $80,000. A particular threat is expected to destroy 25% of the asset's value each time it occurs, and analysts estimate it will occur twice per year. What is the Annualized Loss Expectancy (ALE)?
Show answer & explanation
Correct answer: C - $40,000
Domain 3: Managing a Security Operations Center
Question 3
A dispute arises over who may approve the classification level of a sensitive customer database. According to standard data governance roles, who is ACCOUNTABLE for assigning that classification?
Show answer & explanation
Correct answer: B - The data owner, who holds business accountability for the information asset and its classification
Domain 5: Managing Artificial Intelligence
Question 4
A security architect is redesigning network access so that no user or device is trusted merely because it sits inside the corporate network; every request must be authenticated and authorized. Which model BEST describes this approach?
Show answer & explanation
Correct answer: C - Zero Trust, applying 'never trust, always verify' regardless of location
Domain 6: Managing Cloud Security
Question 5
Security operations reports that a piece of malware spread across hundreds of hosts overnight without any user opening a file or clicking a link. This self-propagating behavior is MOST characteristic of a:
Show answer & explanation
Correct answer: A - Worm
Domain 7: Managing Encryption and Privacy
Question 6
An organization runs virtual machines on an Infrastructure-as-a-Service (IaaS) platform. Under the cloud shared responsibility model, who is responsible for securing the DATA and the guest operating system stored on those VMs?
Show answer & explanation
Correct answer: A - The customer, since IaaS leaves the OS and data to the customer
Domain 8: Managing Negotiations and Vendors
Question 7
A manager wants to send a partner a file so that ONLY that partner can decrypt it. Using asymmetric cryptography, which key should be used to encrypt the file?
Show answer & explanation
Correct answer: D - The recipient's public key
Domain 12: Managing System Security
Question 8
A vulnerability report lists an identifier of 'CVE-2024-XXXXX' alongside a numeric rating of 9.8. What does that numeric 9.8 rating represent?
Show answer & explanation
Correct answer: B - The CVSS score expressing the severity of the vulnerability
Domain 16: Networking Concepts for Managers
Question 9
A SOC already aggregates and correlates log data to generate alerts, but analysts are overwhelmed manually executing the same containment steps for every phishing alert. Which technology is specifically designed to AUTOMATE that repeatable response through playbooks?
Show answer & explanation
Correct answer: D - A SOAR platform that runs the response steps automatically
Domain 18: Vulnerability Management
Question 10
A business unit tells the security leader it can tolerate losing at most 15 minutes of transaction data if a system fails. This 15-minute figure defines which business continuity metric?
Show answer & explanation
Correct answer: B - Recovery Point Objective (RPO)