
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 3
Security Program Analysis GSTRT Practice Questions (Page 2)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 6–10
- 6
What is the primary purpose of considering organizational culture in security program analysis?
Select an answer first - 7
A mid-sized financial services firm is conducting its annual security program assessment. The CISO notes that the current program has strong technical controls but the business is planning to launch a new mobile banking app within six months. The assessment team must evaluate whether the current security program can support this initiative. Which approach best aligns the assessment with the business objective?
Select an answer first - 8
A nonprofit organization's core values emphasize transparency, collaboration, and minimal intrusion into donor privacy. The security team proposes a new monitoring solution that logs all employee web activity and flags any access to social media. The executive director is concerned about the cultural fit. What should the security team do to align the proposal with organizational values?
Select an answer first - 9
A regional bank is expanding its digital services and plans to launch a mobile payment app within 12 months. The current security program has strong network perimeter controls and an experienced incident response team, but no formal vulnerability management process and limited cloud security expertise. The bank's board has asked the CISO to identify the most critical gap to address first to support the new initiative. What should the CISO prioritize?
Select an answer first - 10
A construction company has a culture that values practical experience over formal training. Many field workers do not regularly check email. The security team is analyzing the program and needs to improve security awareness among field workers. What approach is most likely to be effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.