
GIAC Critical Controls Certification
Domain 4Objective 1
Data Protection GCCC Practice Questions (Page 7)
Part of the Data Protection and Recovery domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
14concepts
Questions 31–35
- 31
A company is subject to a regulation that requires retaining financial records for 7 years. The company also has a business policy to delete customer personal data after 3 years of inactivity. A customer account has been inactive for 3 years, but the account contains financial transaction records. Which action BEST complies with both requirements?
Select an answer first - 32
A company determines that it can tolerate losing at most 30 minutes of transaction data in a disaster. What is the required RPO?
Select an answer first - 33
Which mechanism is used to keep data available in the event of a hardware failure?
Select an answer first - 34
What does Recovery Point Objective (RPO) define?
Select an answer first - 35
Which term represents the maximum time a system can be down before it must be restored to avoid unacceptable business impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.