
GIAC Critical Controls Certification
Domain 4Objective 1
Data Protection GCCC Practice Questions (Page 3)
Part of the Data Protection and Recovery domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 11–15
- 11
What is the main purpose of a data retention policy?
Select an answer first - 12
A critical application must be back online within 4 hours of a failure. What is the RTO for this application?
Select an answer first - 13
A company stores sensitive customer data in a cloud object storage service. The data is encrypted at rest using server-side encryption. The company's security team wants to ensure that even the cloud provider cannot access the plaintext data. Which approach should the company use?
Select an answer first - 14
A security analyst is investigating a potential data breach. The company stores sensitive data in a database with encryption at rest and access logging enabled. The analyst needs to determine whether any unauthorized access occurred. Which evidence source is most useful?
Select an answer first - 15
A security analyst is reviewing the data protection controls for a system that stores customer payment information. The system currently uses encryption at rest and in transit, but there is no data classification scheme. The analyst wants to ensure that the protection controls are appropriate for the data sensitivity. Which action should the analyst take FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.