
GIAC Defensible Security Architect
Domain 4Objective 1
Data-Centric Security GDSA Practice Questions (Page 4)
Part of the Data Protection and Governance domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 16–20
- 16
Which mechanism is commonly used to visually indicate the classification level of a document or email?
Select an answer first - 17
What is the primary goal of the principle of least privilege in data access governance?
Select an answer first - 18
What is the primary purpose of Data Rights Management (DRM) in the context of data-centric security?
Select an answer first - 19
In a cloud environment, what does the 'shared responsibility model' imply for data security?
Select an answer first - 20
A financial institution needs to provide external auditors with read-only access to specific transaction records for a limited time. The auditors are not part of the organization's Azure AD. The institution must ensure that access is revoked automatically after 30 days and that all access is logged. Which approach should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.