
GIAC Defensible Security Architect
Domain 4Objective 1
Data-Centric Security GDSA Practice Questions (Page 1)
Part of the Data Protection and Governance domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 1–5
- 1
A manufacturing company collects sensor data from its production lines. The data is initially stored in a high-performance database for real-time monitoring, then moved to a data lake for long-term analytics, and finally archived to cold storage after 5 years. They need to ensure that the data is encrypted at every stage and that deletion is secure. Which approach should they use?
Select an answer first - 2
A company is migrating its customer database to a public cloud object storage service. The security team must ensure that the data is protected at rest and that access is controlled based on the sensitivity labels assigned to each object. Which combination of controls should they implement?
Select an answer first - 3
A hospital is designing a data-centric security architecture for its electronic health records (EHR) system. The system must support emergency access where a clinician can override normal access controls to view a patient's record during a life-threatening situation. The override must be recorded and reviewed. The architecture must also enforce least privilege for routine access. Which design best meets these requirements?
Select an answer first - 4
A company's DLP solution flags an employee who is uploading customer data to a personal cloud storage account. The employee claims it is for legitimate work-from-home purposes. What should the security team do first?
Select an answer first - 5
A financial services firm stores customer account numbers in a legacy database that cannot be modified to support field-level encryption. The compliance team requires that the data be unreadable if the database backup is stolen, but application developers still need to perform exact-match lookups on the account numbers for daily operations. Which data protection approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.