
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 1
Policy Development GSTRT Practice Questions (Page 4)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
Questions 16–20
- 16
Which event should trigger a review of a security policy?
Select an answer first - 17
A government agency is developing a policy for handling classified information. The policy must ensure that data is not altered during transmission and that only authorized personnel can access it. Which combination of security principles should the policy emphasize?
Select an answer first - 18
In a typical security documentation hierarchy, which document provides the specific step-by-step actions required to complete a task?
Select an answer first - 19
What is the first step in the security policy development process?
Select an answer first - 20
Which document type is best described as 'recommended' rather than mandatory, providing best practices or optional approaches?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.