Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 2Objective 4

Security Program Development GSTRT Practice Questions (Page 1)

Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 1–5

  1. 1expert · hard

    A company is developing a security roadmap. The company has a mature security program but wants to improve its incident response capabilities. The CISO has identified two projects: implementing a SOAR platform and conducting regular tabletop exercises. The budget allows for only one project this year. Which project should the CISO choose?

    Select an answer first
  2. 2expert · hard

    A security team is implementing a new metrics program. The CISO wants to report to the board on the program's effectiveness. The team has proposed several metrics. Which metric is most likely to be meaningful to the board?

    Select an answer first
  3. 3expert · hard

    A global bank is developing a security roadmap. The bank's strategic priorities include expanding into emerging markets and complying with new data protection regulations. The security team has a limited budget and must choose between investing in advanced threat detection or in compliance automation. Which approach best balances the competing priorities?

    Select an answer first
  4. 4application · medium

    A non-profit organization is developing a security roadmap. The organization has a very limited budget and relies heavily on volunteers. The board wants to see a plan that is realistic and achievable. Which approach should the security team take?

    Select an answer first
  5. 5expert · hard

    A multinational corporation is rolling out a new security program that includes data loss prevention (DLP) and stricter remote access controls. The European works council is concerned about employee privacy. The CISO must socialize the program to gain acceptance. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.