
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 2
Policy Management GSTRT Practice Questions (Page 1)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
4concepts
Questions 1–5
- 1
A software company's security policy requires that all code be reviewed by a second developer before deployment. The development team has a procedure that requires code review for all changes to the main branch. A recent incident occurred because a change was deployed to a feature branch without review, and that branch was later merged. What is the most appropriate action?
Select an answer first - 2
A financial institution has a security policy that requires all employees to use a VPN when working remotely. The policy was approved by the board, but the IT department has not updated the VPN procedure to reflect a new authentication method that was deployed last month. The new authentication method is more secure but requires employees to use a hardware token. Several employees have complained that the new procedure is confusing. What should the IT department do?
Select an answer first - 3
A government agency has a security policy that requires all employees to use a specific encrypted email service for sending sensitive information. The IT department has a procedure that describes how to configure the email service, but the procedure was written for an older version of the software. The new version has a different configuration interface. What should the IT department do?
Select an answer first - 4
A regional bank is updating its security policies to align with a new state data-privacy regulation that requires customer financial data to be stored within the state's borders. The bank's current policy states that all data is stored in a single cloud region in a neighboring state. The CISO asks you to revise the policy. What is the most appropriate first step?
Select an answer first - 5
A non-profit organization has a security policy that was approved by the board of directors five years ago. The policy has not been reviewed since. The new executive director wants to ensure the policy is still relevant. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.