
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 3
Security Program Analysis GSTRT Practice Questions (Page 5)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 21–25
- 21
A government contractor's core values include integrity, accountability, and public service. The security team is evaluating a new threat intelligence platform that would automatically share threat data with a commercial vendor. The legal team raises concerns about data privacy and the contractor's obligation to protect sensitive information. What should the security team do to align with organizational values?
Select an answer first - 22
A family-owned retail chain has a culture of trust and informal communication. Employees frequently share passwords to access shared systems, and the current security policy prohibits this but is rarely enforced. The company's values emphasize family and mutual support. The security manager is conducting a program analysis and must address the password-sharing issue. What is the most effective approach?
Select an answer first - 23
Which of the following inputs is most relevant when forecasting future security needs for an organization?
Select an answer first - 24
A manufacturing company currently relies on legacy on-premises systems and has no cloud presence. The company plans to double its e-commerce sales in two years and will migrate customer-facing systems to a public cloud provider. The security team currently uses a traditional perimeter-focused model. What is the most important future security requirement to plan for now?
Select an answer first - 25
A non-profit organization has a culture of openness and information sharing, with few formal security controls. The security program assessment reveals that employees frequently share sensitive donor information via unencrypted email. The organization's leadership values collaboration. What is the most effective way to address this issue while respecting the culture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.