
GIAC Cloud Security Architecture and Design
Domain 2Objective 3
Network Firewalls and Traffic Inspection GCAD Practice Questions (Page 2)
Part of the Network Architecture and Security domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
Questions 6–10
- 6
A security team is considering implementing SSL/TLS inspection on their NGFW. They are concerned about privacy and compliance. Which of the following is a critical consideration they must address?
Select an answer first - 7
Which placement strategy best supports a defense-in-depth approach for a cloud workload that includes a public-facing load balancer, application servers, and a database?
Select an answer first - 8
Which traffic inspection method examines the payload of packets to identify application-layer protocols and detect malicious content?
Select an answer first - 9
In a cloud architecture, where should a network firewall be placed to enforce a security boundary between a public-facing web tier and an internal application tier?
Select an answer first - 10
A security operations team is setting up firewall logging for a multi-tier application. They want to ensure that logs are available for incident response and that they can detect anomalies such as port scanning. Which logging configuration is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.