
GIAC Security Leadership
Domain 1Objective 1
Managing Security Policy GSLC Practice Questions (Page 6)
Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
6concepts
Questions 26–30
- 26
A company's security policy review committee is divided: some members want to update the policy immediately due to a new threat, while others want to wait for the scheduled annual review. The CISO must decide. What is the best approach?
Select an answer first - 27
A healthcare organization's security policy review is due. The compliance officer wants to ensure the policy still meets regulatory requirements. Which action should be part of the review process?
Select an answer first - 28
A large enterprise is restructuring its security governance. Currently, each business unit creates its own security policies, leading to inconsistencies and gaps. The CISO wants to improve governance. What is the most effective change?
Select an answer first - 29
A multinational corporation has a policy that all personal data must be stored in the region where the data subject resides. The company's cloud provider offers regions in multiple countries. The security team is tasked with enforcing this policy. What is the most effective technical control?
Select an answer first - 30
An organization's security policy on data retention was created before the adoption of cloud storage. The policy does not address data stored in cloud services. The security manager needs to ensure the policy remains relevant. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.