
GIAC Defensible Security Architect
The GIAC Defensible Security Architect (GDSA) certification validates your ability to architect comprehensive defenses that balance prevention, detection, and response. It is designed for security architects, network engineers, and senior security professionals who design and implement layered, network-centric and data-centric controls. Earning GDSA proves you can apply Zero Trust principles and build defense-in-depth that is maintainable and effective.
602 practice questions · Updated 2026-07-30
5Domains
13Objectives
108Concepts
602Questions
GDSA Curriculum
Every domain, objective, and concept the GDSA exam measures.
- Zero Trust Core Principles
- Zero Trust Architecture Components
- Trust Boundaries and Implicit Trust
- Zero Trust vs. Traditional Security Models
- Zero Trust Deployment Models
- Zero Trust Benefits and Challenges
- Zero Trust Endpoint Definition
- Endpoint Trust Assessment
- Endpoint Identity and Authentication
- Endpoint Posture and Health Checks
- Endpoint Segmentation and Micro-segmentation
- Endpoint Access Control Policies
- Endpoint Monitoring and Visibility
- Endpoint Remediation and Response
- Zero Trust Networking Fundamentals
- Microsegmentation
- Identity-Based Access Control
- Encryption and Secure Communication
- Network Visibility and Analytics
- Policy Enforcement Points
- Zero Trust Network Deployment Strategies
- Defense in Depth
- Security Architecture Principles
- Trust Boundaries
- Security Zones
- Reference Architectures
- Threat Modeling
- Risk Management in Architecture
- Layer 3 Defense Fundamentals
- IP Addressing and Subnetting
- Routing Protocols and Security
- Access Control Lists (ACLs)
- Network Address Translation (NAT)
- Firewall Filtering at Layer 3
- ICMP and Its Security Implications
- IP Spoofing and Anti-Spoofing Measures
- Layer 3 Tunneling and VPNs
- Logging and Monitoring at Layer 3
- Layer 1 Physical Layer Defense
- Layer 2 Data Link Layer Defense
- Layer 2 Attack Mitigation
- Spanning Tree Protocol Security
- DHCP Snooping and Dynamic ARP Inspection
- Layer 2 Segmentation and Isolation
- Defense-in-Depth
- Network Segmentation
- Firewalls
- Intrusion Detection and Prevention Systems (IDS/IPS)
- Virtual Private Networks (VPNs)
- Network Access Control (NAC)
- Secure Network Architecture
- Monitoring and Logging
- Proxy Server Fundamentals
- Forward vs. Reverse Proxies
- Proxy Security Controls
- Firewall Fundamentals
- Firewall Rule Design
- Firewall Deployment Architectures
- Proxy and Firewall Integration
- Traffic Inspection and Logging
- Network Encryption Fundamentals
- Symmetric vs. Asymmetric Encryption
- TLS/SSL Protocols
- IPsec VPNs
- Remote Access VPN Technologies
- Wireless Encryption Protocols
- Encryption Key Management
- Network Encryption Architectures
- IPv6 Addressing Basics
- IPv6 Address Types
- IPv6 Address Scopes
- IPv6 Address Configuration
- IPv6 Neighbor Discovery
- IPv6 Security Considerations
- IPv6 Transition Mechanisms
- IPv6 in Network Services
- Data-Centric Security Fundamentals
- Data Classification and Labeling
- Data Protection Controls
- Data Access Governance
- Data Lifecycle Management
- Data-Centric Security Architecture
- Data Loss Prevention (DLP)
- Data Rights Management
- Data-Centric Security in Cloud Environments
- Data-Centric Security Monitoring and Auditing
- Data Discovery
- Data Classification
- Data Governance Frameworks
- Data Lifecycle Management
- Data Mobility Management
- Data Loss Prevention (DLP)
- Data Residency and Sovereignty
- Data Retention and Disposal
- Cloud Security Architecture Principles
- Cloud Deployment Models
- Cloud Service Models
- Cloud Identity and Access Management
- Cloud Data Protection
- Cloud Network Security
- Cloud Workload Security
- Cloud Compliance and Governance
- Cloud Threat Modeling
- Cloud Security Monitoring and Incident Response
- Cloud Security Posture Management
- Cloud-Native Security Services
- Secure Cloud Architecture Patterns
- Cloud Provider Security Features
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GDSA, so none is invented.