Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Strategic Planning, Policy, and Leadership

Domain 3Objective 2

Understanding the Threats GSTRT Practice Questions (Page 8)

Part of the Business and Threat Context domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 9–16 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
5concepts

Questions 36–40

  1. 36application · medium

    A financial institution has detected unusual activity on its network. The activity appears to originate from an internal employee's workstation and involves the exfiltration of customer data. The employee has access to sensitive information as part of their job. Which threat actor category best describes this scenario?

    Select an answer first
  2. 37expert · hard

    A government agency is conducting a threat analysis for its citizen-facing portal. The portal allows citizens to access personal information and submit forms. The agency has identified a potential threat that could allow an attacker to access other citizens' data. The agency has a high risk tolerance for service disruption but a low tolerance for data breaches. The threat modeling team must decide how to prioritize this threat. Which approach best aligns with the agency's risk tolerance?

    Select an answer first
  3. 38application · medium

    A financial services firm is conducting a threat analysis for its new mobile banking application. The security team has identified a vulnerability in the API gateway. They need to determine the likelihood and impact of exploitation. Which step of the threat analysis process should they perform next?

    Select an answer first
  4. 39application · medium

    A multinational corporation's security operations center receives threat intelligence indicating that a specific advanced persistent threat (APT) group is targeting companies in its industry. The intelligence includes indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs). What is the most effective initial use of this intelligence?

    Select an answer first
  5. 40expert · hard

    A large organization is integrating threat intelligence into its risk management process. The security team has access to a commercial threat intelligence platform that provides real-time alerts. However, the alerts are not integrated with the organization's asset inventory. What is the most effective way to use this intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.