
GIAC Cloud Security Architecture and Design
Domain 3Objective 1
Data Security GCAD Practice Questions (Page 9)
Part of the Data Protection and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 41–45
- 41
What is the purpose of a data retention policy?
Select an answer first - 42
Which US regulation sets standards for the protection of protected health information (PHI)?
Select an answer first - 43
What is the primary difference between data masking and tokenization?
Select an answer first - 44
A company is implementing a data classification scheme. The company has a mix of public marketing materials, internal project plans, and customer personal data. The security team wants to apply different security controls based on classification. Which approach should they take?
Select an answer first - 45
During which data lifecycle stage is it most important to enforce data loss prevention (DLP) policies to prevent unauthorized transmission of sensitive data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.