Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 4Objective 2

Data Discovery, Governance, and Mobility Management GDSA Practice Questions (Page 1)

Part of the Data Protection and Governance domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts

Questions 1–5

  1. 1application · medium

    A multinational company allows employees to transfer files between regional offices using a cloud storage service. The compliance team is concerned about sensitive data crossing borders without authorization. They want to monitor and control these transfers while ensuring that data remains in approved geographic regions. Which control combination best meets these needs?

    Select an answer first
  2. 2expert · hard

    A healthcare organization is implementing a data governance framework. They need to ensure that patient data is classified consistently across all departments, that retention periods comply with regulations, and that disposal is approved by the appropriate authority. The organization has a decentralized structure where each department manages its own data. Which approach should they take?

    Select an answer first
  3. 3application · medium

    A multinational corporation is establishing a data governance framework to manage customer data across its subsidiaries. The legal team requires that data be classified according to sensitivity, and that retention periods be enforced based on regulatory requirements. The company wants a single framework that defines roles and responsibilities for data stewardship. What should the security architect recommend?

    Select an answer first
  4. 4application · medium

    A multinational company needs to allow employees to share files with external partners, but must ensure that sensitive data is not shared with unauthorized parties. They also need to comply with data residency laws that restrict where data can be stored. Which solution should they implement?

    Select an answer first
  5. 5expert · hard

    A global company allows employees to use personal devices to access corporate data. The company must comply with data residency laws that restrict where data can be stored and processed. They also want to prevent sensitive data from being transferred to unauthorized locations. What is the most effective approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.