GSLC-2020 Sample Questions

GSLC-2020 Sample Questions & Answers

Managing application security, the overall program structure, and risk frameworks share the heaviest weighting, spread among a long list of leadership topics: cryptography, incident response, SOC oversight, cloud and AI security, vendor and project management, and more.

Launch the full GSLC-2020 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Managing the Program Structure · Program Design

    Case Study

    A mid-sized financial services firm, FinSecure, has recently decided to migrate a significant portion of its on-premises infrastructure to a public cloud provider. The CISO, reporting to the CIO, has been tasked with leading this initiative from a security perspective. The company culture is highly risk-averse, and the board is concerned about meeting stringent regulatory compliance requirements (like PCI DSS and GDPR) in the cloud. The project team is composed of traditional network and system administrators who have limited cloud experience.

    The CISO's primary objective is to build a secure and compliant cloud environment without stifling the agility benefits the company hopes to gain. The initial project plan from the IT team focuses heavily on a 'lift-and-shift' migration of existing virtual machines and security appliances. The CISO is concerned this approach will not adequately address cloud-native security challenges and may be more costly in the long run.

    What is the most effective strategy the CISO should advocate for to ensure the long-term security and success of the cloud migration project?

    Show answer & explanation

    Correct answer: C

    This strategy addresses the root causes of the problem: lack of cloud experience, a flawed migration plan, and compliance concerns. Establishing a CCoE builds internal expertise. Developing a framework based on the Shared Responsibility Model clarifies security roles. Prioritizing re-architecture with cloud-native controls is more secure, scalable, and cost-effective than a simple 'lift-and-shift' of legacy security models. This demonstrates strategic leadership that balances security, compliance, and business agility.

  2. Question 2Beginner

    Managing a Security Operations Center · SOC Operations

    A SOC manager is evaluating technologies to reduce analyst fatigue and improve response times. They are considering a SOAR (Security Orchestration, Automation, and Response) platform. What is the primary function of a SOAR platform in a SOC environment?

    Show answer & explanation

    Correct answer: C

    The core value of a SOAR platform is automation and orchestration. It integrates with other security tools (like SIEM, EDR, firewalls) and uses predefined 'playbooks' to automate sequences of actions, such as enriching alerts, quarantining hosts, or blocking IP addresses. This frees up analysts from repetitive tasks to focus on more complex investigations.

  3. Question 3Advanced

    Managing Application Security · SDLC Security

    As part of integrating security into a mature CI/CD pipeline, a security architect recommends several testing methodologies. Which approach uses instrumentation within a running application during dynamic testing to identify vulnerabilities in real-time?

    Show answer & explanation

    Correct answer: D

    IAST is the methodology that combines elements of both SAST and DAST. It works by deploying an agent that instruments the application code. As automated or manual dynamic tests are performed, the IAST agent observes the application's behavior from the inside, allowing it to pinpoint the exact line of code responsible for a vulnerability with high accuracy.

  4. Question 4Intermediate

    Managing System Security · Endpoint Protection

    A security manager is defining endpoint protection requirements for a company with a large remote workforce. The primary concerns are zero-day threats and fileless malware. Which technology is most essential for addressing these specific threats?

    Show answer & explanation

    Correct answer: C

    Traditional AV is ineffective against zero-day and fileless attacks because they lack known signatures. EDR solutions excel here by focusing on behavioral analysis. They monitor system processes, memory, and network connections for anomalous activities (TTPs - Tactics, Techniques, and Procedures) indicative of an attack, regardless of whether a malicious file is present. This makes EDR critical for detecting modern, sophisticated threats.

  5. Question 5Intermediate

    Managing Security Policy · Policy Development

    A company's Acceptable Use Policy (AUP) is outdated and widely ignored by employees. The security manager needs to revitalize the policy framework. Which of the following is the most important factor for creating an effective and enforceable AUP?

    Show answer & explanation

    Correct answer: B

    A policy without executive sponsorship and clear communication is merely a suggestion. For an AUP to be effective, it must have visible support from leadership, be clearly and regularly communicated to all employees in understandable language, and have well-defined, consistently applied consequences for violations. This creates a culture of accountability and ensures the policy is taken seriously.

  6. Question 6Beginner

    Risk Management and Security Frameworks · Security Frameworks

    A new CISO is hired at a company with a history of underfunding security. To build a business case for increased investment, the CISO decides to align the security program with a well-known framework. Which framework is primarily designed to help organizations improve their cybersecurity risk management by organizing it around the five core functions: Identify, Protect, Detect, Respond, and Recover?

    Show answer & explanation

    Correct answer: C

    The NIST Cybersecurity Framework (CSF) is specifically structured around the five core functions: Identify, Protect, Detect, Respond, and Recover. This structure provides a high-level, strategic view of an organization's cybersecurity risk management capabilities and is widely used to communicate security posture and program needs to business executives.

  7. Question 7IntermediateSelect 3

    Managing Security Awareness · Awareness Program Development

    A manufacturing company is implementing a new security awareness program. The security manager wants to ensure the program is effective and can demonstrate improvement over time. Which THREE of the following are essential components of a mature security awareness program? (Select THREE)

    Show answer & explanation

    Correct answers: B, C, E

    Phishing simulations are a practical way to test and reinforce learning, and tracking metrics like click and report rates provides clear data on program effectiveness and areas for improvement.

    An effective program must empower employees to act. A simple, well-communicated reporting process turns every employee into a potential sensor for the security team.

    Generic, one-size-fits-all training is less effective. A mature program provides targeted education based on the unique risks and access levels of different roles, making the content more relevant and impactful.

  8. Question 8Advanced

    Managing the Program Structure · Program Design

    Case Study

    A retail corporation, 'StyleStream', has experienced rapid growth, leading to a sprawling and poorly documented IT environment. The security team is reactive, primarily dealing with incidents after they occur. The new Director of Security has been given a mandate to establish a proactive security posture. The company has a mix of on-premises data centers, a growing public cloud presence, and hundreds of retail stores with their own local networks.

    The Director's initial assessment reveals several critical issues: no centralized logging, inconsistent endpoint protection, and a lack of visibility into network traffic between different environments. The security team is small and overwhelmed. The Director needs to propose a foundational project that will provide the greatest security value and serve as a platform for future initiatives.

    Which project should the Director champion as the highest priority to build a foundation for proactive security?

    Show answer & explanation

    Correct answer: C

    The fundamental problem is a lack of visibility. Without the ability to see what is happening across the enterprise, security will always be reactive. Implementing a centralized logging and SIEM solution directly addresses this core issue. It provides the necessary visibility to detect threats, respond to incidents, and measure the effectiveness of all other security controls. It is the foundational building block for a proactive security operations capability.

  9. Question 9Intermediate

    Incident Response and Business Continuity · IR Phases

    A security manager is designing a decision-making workflow for the incident response team to handle potential malware infections on executive laptops. The goal is to balance security with operational availability for these critical users. Which of the following represents the most logical decision flow?

    flowchart TD A[Alert Received: Potential Malware on Exec Laptop] --> B{Isolatable from Network?}; B -->|Yes| C[Isolate Host]; B -->|No| D[Notify User & Monitor Closely]; C --> E{Can Malware be Removed Cleanly?}; E -->|Yes| F[Remove Malware & Restore]; E -->|No| G[Reimage Laptop from Gold Standard]; D --> G; F --> H([Close Incident]); G --> H;

    Show answer & explanation

    Correct answer: B

    The depicted workflow follows a sound incident response logic. It prioritizes containment (isolation) if possible, assesses the situation, and chooses a recovery path (clean vs. reimage) based on the assessment. It also includes a contingency path for non-isolatable hosts. This represents a practical and effective process for handling such incidents.

  10. Question 10Beginner

    Network Security Architecture · Architecture Design

    A security leader is explaining the Zero Trust security model to a non-technical audience. What is the core principle of a Zero Trust architecture?

    Show answer & explanation

    Correct answer: C

    The fundamental tenet of Zero Trust is the elimination of the concept of a trusted internal network and an untrusted external network. Instead, it assumes that breach is inevitable and treats every access request—whether from inside or outside the traditional perimeter—as untrusted. Every request must be authenticated, authorized, and encrypted before access is granted.

Ready for the real thing?

The full GSLC-2020 simulator has every exam-style question, timed mode, and instant scoring.