Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 1Objective 2

Managing the Program Structure GSLC Practice Questions (Page 8)

Part of the Security Management and Governance domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A multinational corporation is aligning its security program with the organization's new strategic objective to enter a highly regulated market (e.g., pharmaceutical manufacturing). The current program is centralized, with all security decisions made at headquarters. The company's business units have historically operated with significant autonomy. The CISO must balance the need for consistent security governance with the flexibility required by regional regulatory differences. Which approach best reconciles these competing constraints?

    Select an answer first
  2. 37application · medium

    A financial institution's security program has been running for two years. An annual audit revealed several control gaps and a changing threat landscape. The CISO wants to ensure the program structure evolves to address these findings. Which action best supports continuous improvement?

    Select an answer first
  3. 38application · medium

    A non-profit organization's security program has been operating for a year. The executive director wants to understand the program's value and progress. The CISO must establish a reporting mechanism that effectively communicates program status to the board. Which reporting approach is most appropriate?

    Select an answer first
  4. 39foundation · easy

    What is the primary consideration when allocating budget for a security program?

    Select an answer first
  5. 40expert · hard

    A mid-sized company has a security program with a flat budget. The CISO must choose between two initiatives: (1) upgrading the SIEM platform to improve threat detection, or (2) hiring a dedicated threat hunter. The company has a small security team that is currently overwhelmed with alerts. The board wants to see a reduction in mean time to detect (MTTD) and respond (MTTR). Which decision best addresses the board's objective within the budget constraint?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.