
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 2
Policy Management GSTRT Practice Questions (Page 2)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
4concepts
Questions 6–10
- 6
A bank's security policy requires that all changes to the production environment be approved by the change advisory board (CAB). The DevOps team has a procedure that allows automated deployments to production without CAB approval for low-risk changes. The security team's audit found that a low-risk change caused a data breach. The CISO must reconcile the policy with the DevOps team's need for speed. What is the most appropriate action?
Select an answer first - 7
A manufacturing company has a security policy that requires all remote access to the corporate network to be protected by multi-factor authentication (MFA). The current procedure for remote access only requires a VPN connection with a username and password. The IT team is about to deploy a new MFA solution. What should the IT team do to ensure the procedure aligns with the policy?
Select an answer first - 8
A healthcare organization's incident-response policy was last reviewed two years ago. After a recent ransomware attack, the post-incident review identified that the policy did not clearly define when to involve law enforcement, and the response team wasted time debating this during the incident. The CISO wants to prevent this from recurring. What should you do?
Select an answer first - 9
What is the relationship between security procedures and security policies?
Select an answer first - 10
A multinational corporation has a security policy that was approved by the CISO and distributed via email to all employees two years ago. Since then, the company has acquired two smaller firms and adopted a new cloud-based HR system. The security team notices that employees from the acquired firms have not received the policy, and the HR system's data handling practices are not covered by the existing policy. What should the security team do to address this situation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.