Skip to content

GSLC-2020 Gslc Practice Questions

Prepare for GSLC-2020 with more than an answer.

224 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$999 USD
Level
Management/Leadership
Valid for
4 years
Domains covered on the exam 18
  1. Cryptography Concepts for Managers6%
  2. Incident Response and Business Continuity8%
  3. Managing a Security Operations Center7%
  4. Managing Application Security7%
  5. Managing Artificial Intelligence4%
  6. Managing Cloud Security8%
  7. Managing Encryption and Privacy6%
  8. Managing Negotiations and Vendors5%
  9. Managing Projects6%
  10. Managing Security Awareness5%
  11. Managing Security Policy6%
  12. Managing System Security7%
  13. Managing the Program Structure8%
  14. Network Monitoring for Managers6%
  15. Network Security Architecture7%
  16. Networking Concepts for Managers5%
  17. Risk Management and Security Frameworks8%
  18. Vulnerability Management6%
  1. 1

    During a project planning meeting for a new customer-facing application, the lead developer suggests that security testing can be performed just before the production release to save time. As the security manager, what is the most significant risk of this approach?

    Show answer details

    Correct answer: B

    This is a core principle of 'shifting left' in DevSecOps. Finding and fixing a security flaw during the design or coding phase is significantly cheaper and easier than finding it in a fully built application right before launch. Late-stage discovery can lead to major architectural changes, extensive rework, and significant project delays or the release of a vulnerable product.

  2. 2

    True or False: In asymmetric cryptography, a message encrypted with a recipient's public key can only be decrypted by that same public key.

    Show answer details

    Correct answer: B

    This statement is false. In asymmetric (or public-key) cryptography, the key pair is mathematically linked. A message encrypted with the public key can ONLY be decrypted by the corresponding private key. This is the fundamental principle that ensures confidentiality.

  3. 3

    A security manager must choose between qualitative and quantitative risk analysis to assess a new data-sharing partnership. The primary goal is to quickly communicate the risk level to the board and prioritize mitigation efforts, but there is very little historical data on potential financial losses. Which method is more appropriate and why?

    Show answer details

    Correct answer: B

    Qualitative risk analysis is the better choice in this scenario. It relies on expert judgment and scales (like High/Medium/Low) to assess probability and impact. This makes it much faster to perform and easier to communicate to a non-technical board. Crucially, it does not depend on historical financial data, which the scenario states is unavailable, making a credible quantitative analysis impossible.

  4. 4

    Case Study

    'Innovate Health', a rapidly growing telehealth company, has a security team that has scaled from 5 to 25 people in one year. The CISO is facing challenges with team morale, high turnover in junior analyst roles, and difficulty in demonstrating the team's value to the executive board. The team is structured in flat silos (SOC, AppSec, GRC) with little cross-functional collaboration. Junior analysts feel there is no clear path for advancement, and senior engineers are bogged down with operational tasks.

    The CISO needs to restructure the team and implement management practices that address these issues. The goal is to improve retention, foster skill development, and better align the security team's activities with business objectives.

    Which of the following is the most comprehensive and effective management strategy for the CISO to adopt?

    Show answer details

    Correct answer: C

    This is a holistic leadership solution. A career framework directly addresses the lack of advancement paths and aids retention. A mentorship program helps develop junior talent and engages senior staff in a rewarding way. Cross-functional teams break down the harmful silos, improve collaboration, and give team members exposure to different areas of security. This multi-faceted approach tackles morale, turnover, and skill development simultaneously.

  5. 5

    A university is designing its Business Continuity Plan (BCP). A critical process identified is the student registration system. The university has determined it can tolerate a maximum of 4 hours of downtime for this system before causing unacceptable disruption. This 4-hour window is known as the:

    Show answer details

    Correct answer: B

    The Recovery Time Objective (RTO) is a business-driven metric that defines the maximum acceptable amount of time a system or process can be unavailable after a disaster or disruption. It dictates the urgency of recovery efforts. The 4-hour tolerance for downtime directly corresponds to the RTO.

  6. 6

    A global logistics company is developing its first formal information security program. The CISO has a limited budget and needs to demonstrate early value to the board. Which of the following approaches represents the most effective initial step in establishing a risk management framework?

    Show answer details

    Correct answer: C

    For a new program with a limited budget, a high-level qualitative risk assessment is the most effective starting point. It allows the CISO to quickly identify and prioritize the most significant risks to critical business functions without the time and resource-intensive nature of a full quantitative analysis or a GRC tool implementation. This approach provides immediate, actionable insights to demonstrate value and guide initial security investments.

  7. 7

    A healthcare provider recently suffered a data breach originating from a third-party billing service. The security manager is now tasked with strengthening the vendor management program. Which TWO of the following controls are most critical to implement to prevent a recurrence? (Select TWO)

    Show answer details

    Correct answer: B, D

    Conducting regular, rigorous security audits (on-site or via documentation review) provides direct evidence of a vendor's security posture and control effectiveness.

    Strong contractual language is fundamental. It legally obligates the vendor to meet specific security standards, report incidents promptly, and allow the organization to verify compliance through audits.

  8. 8

    A security manager is briefing the executive team on the phases of incident response. They want to explain the primary goal of the 'Containment' phase in a way that resonates with business leaders. What is the most accurate and business-focused description of this phase?

    Show answer details

    Correct answer: B

    The core purpose of the Containment phase is to limit the scope and magnitude of the incident. From a business perspective, this means stopping the financial, reputational, and operational bleeding. This description is accurate, concise, and directly relates the technical action to its business impact.

  9. 9

    True or False: A security 'standard' is a high-level, principle-based document that establishes an organization's security intent and goals, while a 'policy' provides mandatory, specific configurations or rules to enforce those standards.

    Show answer details

    Correct answer: B

    This statement has the definitions reversed. A 'policy' is the high-level document outlining goals and intent. A 'standard' is a mandatory document that specifies the technologies, configurations, and rules that must be implemented to comply with the policy.

  10. 10

    A fast-growing e-commerce company is struggling with its vulnerability management program. The security team performs monthly scans, but the development teams are overwhelmed by the volume of findings and are slow to patch. As the security manager, what is the most critical process improvement to implement first?

    Show answer details

    Correct answer: B

    The core problem is not the lack of findings, but the inability to act on them. A risk-based prioritization model is the most crucial first step. It allows the team to focus developers' limited time on the vulnerabilities that pose the greatest actual risk to the business, rather than treating all findings equally. This makes the remediation workload manageable and demonstrably reduces risk.

Create an account to continue.