Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 3

Security Program Analysis GSTRT Practice Questions (Page 8)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 36–40

  1. 36application · medium

    A technology startup has a culture of rapid experimentation and minimal bureaucracy. Developers often deploy code directly to production without going through a formal change management process. The new CISO wants to improve security without stifling innovation. What approach best fits the organizational culture?

    Select an answer first
  2. 37application · medium

    A family-owned retail chain's core values emphasize 'community trust and local service.' The security team is evaluating a new centralized cloud-based surveillance system that would store video footage in a remote data center. The assessment must incorporate the company's values. What should the team do?

    Select an answer first
  3. 38expert · hard

    A global retail company is planning to expand into a new country with strict data residency laws. The company's core value is customer trust. The current security program has strong encryption and access controls but relies on a centralized data center in another region. The CISO must forecast future security needs. What is the most critical requirement?

    Select an answer first
  4. 39application · medium

    A healthcare organization is planning to adopt Internet of Medical Things (IoMT) devices for patient monitoring over the next three years. The current security program has strong data protection policies but no device inventory or segmentation strategy. What future security requirement should be addressed first in the program analysis?

    Select an answer first
  5. 40expert · hard

    A technology company's core values include innovation and speed. The security team proposes a new security awareness program that includes mandatory monthly training and simulated phishing campaigns. The company's culture is informal and employees value their time. The CISO must integrate the program with organizational values. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.