GIAC Strategic Planning, Policy, and Leadership (GSTRT) Sample Questions:
1. Why is it important to document and track all cybersecurity policy exceptions within an organization?
Response:
A) To reduce the need for regular policy updates
B) To monitor policy violations
C) To ensure transparency and accountability, allowing for periodic review and risk assessment of the exceptions
D) To prevent employees from requesting more exceptions
2. What is the primary purpose of managing cybersecurity policies within an organization?
Response:
A) To ensure policies are regularly updated, enforced, and aligned with organizational goals
B) To establish policies and leave them unchanged for several years
C) To make policies flexible enough for employees to interpret them as they wish
D) To create complex policies that are difficult to understand
3. What is the primary goal of Advanced Persistent Threat (APT) actors?
Response:
A) To quickly deface websites
B) To cause immediate disruption and chaos
C) To perform a one-time attack and disappear
D) To establish long-term, covert access to a target's network for espionage or data theft
4. What is a critical outcome of conducting a thorough security gap analysis?
Response:
A) Identifying areas where the current security program is falling short and providing recommendations for improvement
B) Eliminating the need for regular security assessments
C) Reducing the organization's overall cybersecurity budget
D) Replacing the entire security team
5. Your organization has been tasked with developing a comprehensive security program to protect customer data as it expands into new markets. However, the executive team is concerned about the cost of implementing new security measures. How would you approach developing the security program while addressing these concerns?
Response:
A) Develop a business case that highlights the potential risks of not securing customer data, present a phased approach to implementation, and demonstrate the long-term value of the program
B) Postpone the security program until the company grows further
C) Implement only basic security measures to reduce costs
D) Eliminate the security program to avoid costs entirely
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: A | Question # 3 Answer: D | Question # 4 Answer: A | Question # 5 Answer: A |

We're so confident of our products that we provide no hassle product exchange.


By Joanna


