Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 2

Policy Management GSTRT Practice Questions (Page 5)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
4concepts

Questions 21–25

  1. 21application · medium

    A technology company's security policy requires that all software vulnerabilities be patched within 30 days. The operations team has a procedure that patches critical vulnerabilities within 7 days and non-critical ones within 60 days. The security team's quarterly review found that the 60-day window for non-critical patches is causing some systems to miss the policy deadline. What is the most appropriate action?

    Select an answer first
  2. 22application · medium

    A financial services firm's security policy requires that all sensitive data be encrypted at rest. The storage team has a procedure that encrypts all production databases but does not encrypt backup tapes. An internal audit found that backup tapes are stored offsite and contain sensitive data. What is the most appropriate action?

    Select an answer first
  3. 23expert · hard

    An e-commerce company's security policy requires that all customer data be encrypted in transit using TLS 1.2 or higher. The web operations team has a procedure that configures TLS 1.2 on all public-facing web servers. A recent security assessment found that some internal APIs still use TLS 1.0. The CISO must decide how to address this. What is the most appropriate action?

    Select an answer first
  4. 24foundation · easy

    Which process is part of the security policy management lifecycle?

    Select an answer first
  5. 25application · medium

    A software company's password policy requires 12-character passwords changed every 90 days. The security team's annual review found that the password-change requirement is causing users to write down passwords, increasing risk. The team also reviewed current industry guidance, which recommends against forced periodic changes. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.