
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 1
Policy Development GSTRT Practice Questions (Page 3)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
Questions 11–15
- 11
Which security principle is primarily concerned with ensuring that data is not altered or destroyed by unauthorized parties?
Select an answer first - 12
A security policy requires multiple layers of control, such as firewalls, antivirus, and user training. Which security principle does this approach exemplify?
Select an answer first - 13
A financial services firm has a security policy that was last reviewed three years ago. Since then, the company has migrated to a multi-cloud environment and adopted a DevOps model. The policy still references on-premises data centers and does not address cloud security responsibilities. An internal audit has identified this as a significant gap. What is the most appropriate action for the CISO to take?
Select an answer first - 14
Which mechanism is commonly used to enforce a security policy?
Select an answer first - 15
A company has a policy that requires all employees to complete security awareness training annually. An employee has failed to complete the training for two consecutive years. The employee's manager is unsure how to handle this situation. According to the policy, which of the following is the most appropriate action for the manager to take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.