
GIAC Security Leadership
Domain 4Objective 2
Managing Encryption and Privacy GSLC Practice Questions (Page 8)
Part of the Cryptography and Privacy domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 4–6 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 36–40
- 36
What is the primary reason cryptographic keys should be stored separately from the encrypted data?
Select an answer first - 37
During a routine audit, a security analyst discovers that a database containing customer personal data was encrypted with a key that was rotated six months ago, but the old key was not destroyed. The analyst suspects the old key may have been exposed in a phishing incident. What is the FIRST step in the incident response process?
Select an answer first - 38
Which regulation specifically addresses the protection of personal data of individuals in the European Union and includes requirements for encryption and breach notification?
Select an answer first - 39
Which practice aligns with the 'data minimization' principle of Privacy by Design?
Select an answer first - 40
A system administrator needs to set up secure communication between two servers over the internet. The administrator wants to use asymmetric cryptography for key exchange and symmetric cryptography for bulk data encryption. Which protocol best fits this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.