Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 1

Policy Development GSTRT Practice Questions (Page 5)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
8concepts

Questions 21–25

  1. 21application · medium

    A manufacturing company is developing a policy for third-party vendor access to its network. The legal department has identified that the policy must align with a new data protection regulation. The IT team has drafted the policy and is now seeking input from key stakeholders. What is the next step in the policy development process?

    Select an answer first
  2. 22application · medium

    A multinational corporation has just approved a new data-classification policy. The policy introduces mandatory labeling for all documents and emails. The CISO is concerned that employees in different regions may not understand the new requirements. Which communication approach would most effectively support implementation across the organization?

    Select an answer first
  3. 23application · medium

    A technology company has a policy requiring employees to use multi-factor authentication (MFA) for all remote access. An employee has repeatedly failed to enroll in MFA, citing inconvenience. The manager wants to enforce the policy consistently. Which action aligns with the policy hierarchy and enforcement principles?

    Select an answer first
  4. 24application · medium

    A software company is developing a new policy for handling customer data. The company is subject to the Payment Card Industry Data Security Standard (PCI DSS) because it processes credit card payments. During the policy drafting phase, the policy team is unsure how to handle the requirement for encrypting cardholder data at rest. What is the most appropriate source of guidance for this specific requirement?

    Select an answer first
  5. 25application · medium

    A regional bank is drafting a new remote-work security policy. The compliance team has identified that the policy must satisfy a contractual obligation requiring all customer data to remain within the country. The CISO wants the policy to be enforceable and to clearly define who can access customer data from home. Which two elements should the policy draft include to best address these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.