
GIAC Security Leadership
Domain 1Objective 2
Managing the Program Structure GSLC Practice Questions (Page 3)
Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
10concepts
Questions 11–15
- 11
A mid-sized e-commerce company is building its security program structure. The CISO has a limited budget and must decide how to allocate resources. Which approach best ensures the program is effective while respecting the budget constraint?
Select an answer first - 12
A newly appointed CISO is reviewing the security program structure of a company that has grown through acquisitions. Each acquired company has its own security program, policies, and tools. The CISO must create a unified program structure that supports the company's strategic goal of operating as one integrated enterprise while respecting local regulatory requirements. Which approach best achieves this?
Select an answer first - 13
A public sector organization is establishing a security program and must comply with government regulations that require clear accountability for security decisions. The organization has a hierarchical structure with multiple layers of management. Which role assignment best ensures clear accountability?
Select an answer first - 14
A logistics company has implemented a security program and wants to measure its effectiveness. The CISO needs to select KPIs that will provide meaningful insight into the program's performance. Which KPI is most appropriate for measuring the effectiveness of the security program?
Select an answer first - 15
A mid-sized financial services firm is restructuring its security program to align with the organization's new strategic goal of expanding into international markets. The CISO wants the security program structure to support this expansion while maintaining compliance with multiple regional data protection regulations. Which approach best aligns the security program structure with the organization's strategic objectives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.