Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Infrastructure Protection (GCIP)

Domain 5Objective 2

Information Protection GCIP Practice Questions (Page 7)

Part of the Recovery and Information Protection domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 31–35

  1. 31expert · hard

    A corporation is updating its information protection program. The current program lacks a formal disposal process, and old hard drives are stored in a closet. The legal department requires that data be retained for at least five years, but the security team wants to reduce the risk of data breaches. What is the best approach?

    Select an answer first
  2. 32application · medium

    A hospital is disposing of old paper medical records that have passed their retention period. The records contain patient names, diagnoses, and social security numbers. The hospital's disposal policy requires that the information be unreadable and unreconstructable. Which disposal method should be used?

    Select an answer first
  3. 33expert · hard

    A financial institution is building an information protection program. The compliance team has identified that customer financial data is stored in a legacy mainframe, a cloud data warehouse, and on backup tapes. The data is not consistently classified. The institution must meet regulatory requirements that mandate encryption for customer financial data at rest and in transit. What should the institution do FIRST?

    Select an answer first
  4. 34foundation · easy

    What is the primary purpose of identifying and inventorying information assets?

    Select an answer first
  5. 35expert · hard

    A healthcare organization stores patient data in an on-premises EHR system and in a cloud-based analytics platform. The data is classified as 'Confidential'. The organization is required to protect the data with appropriate safeguards. The cloud provider offers encryption at rest, but the organization is concerned about the cloud provider's ability to access the data. What should the organization do to maintain control over the data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIP” is a trademark of its owner, used for identification only.