
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 3
Security Program Analysis GSTRT Practice Questions (Page 7)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 31–35
- 31
A manufacturing company has a culture of continuous improvement and employee empowerment. The company is planning to implement industrial IoT (IIoT) sensors on the factory floor to improve efficiency. The security team must forecast future security needs. The current program has no OT security expertise. What is the most critical future requirement?
Select an answer first - 32
A government contractor has a hierarchical, risk-averse culture where decisions are made at the top. The security program assessment identifies a critical vulnerability in a legacy system, but the remediation requires significant downtime. The security team must present the findings to leadership. How should the team frame the recommendation to align with the organizational culture?
Select an answer first - 33
A financial services firm has a hierarchical culture where decisions are made by senior management and employees are expected to follow procedures exactly. The security team wants to introduce a new phishing simulation program. What is the most culturally appropriate way to implement it?
Select an answer first - 34
A retail company has a strong brand reputation for customer privacy. The security program is mature, but the company is planning to launch a loyalty program that will collect extensive customer data. The CISO must analyze the program's alignment with business objectives. What is the most critical consideration?
Select an answer first - 35
A hospital has a culture of rapid decision-making and high trust in clinicians. The security team is analyzing the program and finds that clinicians often bypass security controls to access patient data quickly. The hospital is planning to implement a new electronic health record (EHR) system. What is the most effective way to address the culture's impact on security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.