
GIAC Defensible Security Architect
Domain 2Objective 2
Fundamental Layer 3 Defense GDSA Practice Questions (Page 5)
Part of the Network Security Fundamentals domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
Questions 21–25
- 21
A network administrator is troubleshooting a BGP peering session between two autonomous systems. The session is established, but routes are not being exchanged. The administrator checks the BGP configuration and finds that the neighbor statement includes a route-map that is applied in the inbound direction. What should the administrator check next?
Select an answer first - 22
What is the primary purpose of Unicast Reverse Path Forwarding (uRPF) on a router?
Select an answer first - 23
Which type of attack is specifically mitigated by implementing anti-spoofing filters such as uRPF?
Select an answer first - 24
A network engineer is troubleshooting intermittent connectivity issues after enabling uRPF in strict mode on the edge router. Internal users report that some legitimate traffic is being dropped. The router has asymmetric routing paths for certain destinations. What is the most likely cause and the best solution?
Select an answer first - 25
Which tool is commonly used to analyze Layer 3 traffic patterns and identify anomalies such as unusual source IP addresses or abnormal packet rates?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.