
GIAC Defensible Security Architect
Domain 4Objective 1
Data-Centric Security GDSA Practice Questions (Page 6)
Part of the Data Protection and Governance domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 26–30
- 26
In a data-centric security architecture, where are security controls typically integrated?
Select an answer first - 27
A hospital wants to design a data-centric security architecture for its electronic health records (EHR) system. The system consists of a web application, a database, and a file storage for scanned documents. They need to ensure that patient data is protected across all layers, and that access is audited. Which architecture best aligns with data-centric principles?
Select an answer first - 28
Which statement best describes the core principle of data-centric security?
Select an answer first - 29
A company is evaluating its security strategy. They currently rely on network segmentation and firewalls to protect data. They want to adopt a data-centric security approach. Which change best reflects this shift?
Select an answer first - 30
Which term describes the ability of a rights management system to enforce policies on a document even after it has been downloaded to a user's device?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.