
GIAC Security Leadership
Domain 4Objective 2
Managing Encryption and Privacy GSLC Practice Questions (Page 6)
Part of the Cryptography and Privacy domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 4–6 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 26–30
- 26
Which practice is considered a key management best practice for cryptographic keys?
Select an answer first - 27
A company's security policy requires that encryption keys be rotated annually and that the loss of a key must not result in permanent data loss. The IT team currently uses a single master key to wrap all data encryption keys. Which improvement best addresses the policy?
Select an answer first - 28
A global company is subject to GDPR and stores personal data in a cloud database. The database is encrypted at rest with keys managed by the cloud provider. The company's legal team is concerned about the provider's ability to access the data. Which approach would BEST address the legal team's concern while maintaining the ability to use the provider's database features?
Select an answer first - 29
A security manager is explaining to a new analyst the basic difference between symmetric and asymmetric cryptography. Which statement correctly describes that difference?
Select an answer first - 30
What is the primary purpose of a data classification scheme in relation to encryption and privacy controls?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.