Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 3Objective 2

Understanding the Threats GSTRT Practice Questions (Page 5)

Part of the Business and Threat Context domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 9–16 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
5concepts

Questions 21–25

  1. 21expert · hard · select all that apply

    A large retail company is integrating threat intelligence into its security program. The company has a distributed infrastructure and a limited security team. The goal is to improve threat detection and response while minimizing false positives and analyst workload. Which of the following strategies best achieve this goal? (Select all that apply.)

    Select an answer first
  2. 22application · medium

    A software company is using the PASTA threat modeling methodology to assess a new cloud-based application. The team is in the stage of identifying potential attack vectors. Which activity is most aligned with this stage?

    Select an answer first
  3. 23application · medium

    A manufacturing company is conducting a threat analysis for its industrial control systems (ICS). The team has identified that a disgruntled former employee with knowledge of the systems could cause physical damage. They need to prioritize this threat. Which factor should be most heavily weighted in their risk assessment?

    Select an answer first
  4. 24expert · hard

    A global bank's threat intelligence team receives a report from a trusted vendor about a new malware family targeting the banking sector. The report includes IOCs and TTPs. The team also has internal data showing that a similar malware was detected in a non-production environment last month. The bank's leadership wants to prioritize actions. What is the most effective approach?

    Select an answer first
  5. 25foundation · easy

    Which step in a structured threat analysis process involves gathering details about a threat's capabilities and methods?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.