
GIAC Critical Controls Certification
Domain 4Objective 1
Data Protection GCCC Practice Questions (Page 1)
Part of the Data Protection and Recovery domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 1–5
- 1
What is the primary purpose of data classification?
Select an answer first - 2
What is the primary purpose of auditing data protection controls?
Select an answer first - 3
A company stores customer payment card data in an on-premises database and also sends daily extracts to a cloud storage bucket for analytics. The security team requires that the data be protected both while stored and while transmitted. Which set of controls BEST meets this requirement?
Select an answer first - 4
A multinational company must retain customer purchase records for 7 years per tax law, but a new privacy regulation requires that personal data not be kept longer than necessary. The company's legal team confirms that after 7 years, the purchase records must be deleted. Which retention and disposal approach BEST satisfies both requirements?
Select an answer first - 5
A company runs a critical application on a virtual machine in a single cloud availability zone. The application's data is stored on a managed disk. The company's RTO is 15 minutes, and the RPO is zero. Which solution best meets these objectives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.