
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 4
Security Program Development GSTRT Practice Questions (Page 6)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 26–30
- 26
What characteristic makes a security metric meaningful for measuring program effectiveness?
Select an answer first - 27
A multinational corporation is rolling out a new security program that includes data classification and access controls. The marketing department is resistant, fearing it will slow down their ability to share campaign materials. The security team must gain buy-in while maintaining the program's integrity. Which approach best achieves this?
Select an answer first - 28
What is the primary goal of socializing a security program with stakeholders?
Select an answer first - 29
A security manager wants to report to senior leadership on the effectiveness of the company's vulnerability management program. Which metric would be most meaningful to senior leadership?
Select an answer first - 30
A financial services firm is rolling out a new data loss prevention (DLP) program. The security team has encountered resistance from the sales department, which fears the DLP controls will slow down their ability to share documents with clients. What is the most effective way to socialize the program and gain buy-in from the sales team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.