
GIAC Defensible Security Architect
Domain 2Objective 1
Fundamental Security Architecture Concepts GDSA Practice Questions (Page 1)
Part of the Network Security Fundamentals domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 1–5
- 1
During a threat modeling session for a new online ordering system, the team identifies that an attacker could exploit a vulnerability in the web server to read the database credentials stored in a configuration file. The team decides to move the credentials to a hardware security module (HSM) and enforce network segmentation between the web and database tiers. Which threat modeling concept does this decision represent?
Select an answer first - 2
During a threat modeling session for a new online payment system, the team identifies that an attacker could exploit a vulnerability in the web server to read the database credentials stored in a configuration file. The team is considering two mitigations: (A) move the credentials to a hardware security module (HSM) and enforce network segmentation between the web and database tiers, or (B) implement a web application firewall (WAF) and rely on the database's built-in encryption. The team has a limited budget and must choose the most effective mitigation. Which choice is better and why?
Select an answer first - 3
A company is connecting its corporate network to a third-party partner network via a VPN. The security architect is defining the trust relationship between the two networks. Which action best establishes a clear trust boundary?
Select an answer first - 4
A system administrator is configuring a new file server. The security policy states that all access should be denied by default and only explicitly permitted access should be allowed. Which configuration aligns with this policy?
Select an answer first - 5
A security architect is designing a new e-commerce platform. The architecture includes a web application firewall (WAF), network segmentation, and host-based intrusion detection. The architect wants to ensure that if an attacker exploits a vulnerability in the web application, the attacker cannot easily move laterally to the payment processing systems. Which combination of controls best supports this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.