Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 3

Security Program Analysis GSTRT Practice Questions (Page 4)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 16–20

  1. 16application · medium

    A multinational corporation is assessing its security program across regional offices. The assessment finds that the Asia-Pacific region has a high rate of security incidents, while the European region has a low rate. The corporate culture is decentralized, with regional autonomy. What should the security team do to improve the program?

    Select an answer first
  2. 17expert · hard

    A mid-sized insurance company has a security program that is technically strong but has low employee compliance with security policies. The company's culture is highly autonomous, and employees resist centralized controls. The company is planning to acquire a smaller firm that has a very different, compliance-driven culture. The CISO must analyze the current program and plan for the merger. What is the most important consideration?

    Select an answer first
  3. 18foundation · easy

    When analyzing a security program, a leader ensures that security decisions reflect the organization's stated principles and mission. Which concept is being applied?

    Select an answer first
  4. 19foundation · easy

    A security leader is tasked with anticipating the security capabilities the organization will need in the next three years, considering the adoption of new technologies and the evolving threat landscape. Which practice does this describe?

    Select an answer first
  5. 20expert · hard

    A technology company's core values include 'innovation and disruption.' The security team is assessing a new initiative to allow employees to bring their own devices (BYOD) to work. The company's culture is flexible and trusts employees. The assessment must incorporate the company's values. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.