Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 3

Security Program Analysis GSTRT Practice Questions (Page 6)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 26–30

  1. 26application · medium

    An educational institution values academic freedom and open access to information. It is planning to implement a new research collaboration platform that will allow external partners to access internal systems. The security team must forecast future security needs. What should be the primary consideration?

    Select an answer first
  2. 27application · medium

    A logistics company has a mature security program with strong endpoint protection and a well-staffed SOC, but its business is expanding into new international markets. The CISO is analyzing the program's alignment with business objectives. What is the most important factor to evaluate?

    Select an answer first
  3. 28expert · hard

    A merger between two companies is underway. Company A has a security culture of 'security by default' with strict controls, while Company B has a culture of 'enablement first' with minimal controls. The security team must conduct a program assessment for the merged entity. The business objective is to integrate operations quickly while maintaining security. What is the most effective approach?

    Select an answer first
  4. 29expert · hard

    A hospital system is conducting a security program assessment. The organization's mission emphasizes 'compassionate care and community service.' The assessment reveals that the current security program is technically strong but has a weak incident response process that could delay patient care during a cyberattack. The board is considering whether to invest in a new security operations center (SOC) or improve the incident response plan. The hospital's culture is collaborative and patient-focused. Which recommendation best aligns with the organization's mission and addresses the assessment finding?

    Select an answer first
  5. 30foundation · easy

    A security analyst notices that employees frequently bypass security procedures because they value speed and convenience over formal processes. When analyzing the security program, which factor is most important to consider?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.