Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 3

Security Program Analysis GSTRT Practice Questions (Page 1)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 1–5

  1. 1application · medium

    A technology startup has a culture of rapid experimentation and minimal documentation. The security team is conducting a program assessment and finds that the existing security policies are often bypassed because they are seen as 'red tape.' How should the security team adapt its analysis to this cultural reality?

    Select an answer first
  2. 2foundation · easy

    Why is it important to incorporate an organization's core values into security program analysis?

    Select an answer first
  3. 3application · medium

    A logistics company is considering adopting IoT sensors for fleet tracking. The security team is forecasting future security needs. Which emerging threat should be prioritized in the analysis?

    Select an answer first
  4. 4application · medium

    A financial institution's strategic plan includes adopting artificial intelligence for fraud detection. The security team must forecast future security needs. The institution's core value is 'customer trust through transparency.' Which approach best aligns future security planning with this value?

    Select an answer first
  5. 5expert · hard

    A global e-commerce company is planning to expand into a new region with strict data residency laws. The company's culture is data-driven and innovative, but the security team is concerned about the increased complexity. The current security program is mature but not designed for multi-region compliance. The team must forecast future security needs. What is the most critical factor to consider?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.