Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 2

Policy Management GSTRT Practice Questions (Page 4)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
4concepts

Questions 16–20

  1. 16application · medium

    A university's acceptable-use policy (AUP) was written when all students used university-provided laptops. Now, most students bring personal devices, and the policy does not address personal-device usage on the campus Wi-Fi network. The security team has noticed an increase in malware infections on personal devices. What is the most appropriate action?

    Select an answer first
  2. 17application · medium

    A technology startup has a security policy that was created by the founding team and has never been formally reviewed. The company has grown from 10 to 200 employees, and the policy does not cover cloud-based collaboration tools that are now widely used. The new CISO wants to establish a formal policy management process. What should the CISO do first?

    Select an answer first
  3. 18expert · hard

    A hospital's security policy requires that all access to patient records be logged and reviewed monthly. The IT team has a procedure that reviews access logs for the electronic health record (EHR) system, but not for the lab information system (LIS), which also contains patient data. A recent audit found that a former employee accessed patient records in the LIS after termination. The CISO must decide how to address this. What is the most appropriate action?

    Select an answer first
  4. 19foundation · easy

    When a security policy is updated, what should happen to related security procedures?

    Select an answer first
  5. 20foundation · easy

    During a security policy assessment, what is the primary purpose of comparing existing policies against regulatory requirements and industry best practices?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.