Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 2Objective 1

Fundamental Security Architecture Concepts GDSA Practice Questions (Page 4)

Part of the Network Security Fundamentals domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
7concepts

Questions 16–20

  1. 16foundation · easy

    In risk management, what does the term 'residual risk' refer to?

    Select an answer first
  2. 17expert · hard

    A security architect is designing a system where a third-party contractor must be able to upload files to a server, but must not be able to read files uploaded by other contractors. The architect is considering using separate folders for each contractor and setting permissions accordingly. Which additional principle must be applied to ensure that the contractor cannot access other contractors' files through a misconfigured application?

    Select an answer first
  3. 18expert · hard

    A company is integrating a new acquisition's network with its own. The acquired company has a flat network and no internal segmentation. The security architect must integrate the two networks while maintaining a strong security posture. The architect proposes placing a firewall between the two networks and treating the acquired network as a lower-trust zone. Which additional action is most important to ensure the trust boundary is effective?

    Select an answer first
  4. 19application · medium

    A company is evaluating whether to add a web application firewall (WAF) in front of its public website. The risk assessment shows that the website has a high likelihood of being attacked, but the impact of a successful attack is moderate. The security team has a limited budget and must choose between the WAF and additional security awareness training for developers. Which decision best reflects risk management principles?

    Select an answer first
  5. 20application · medium

    A hospital is segmenting its network to protect patient records. The IT team wants to ensure that a compromised workstation in the general office zone cannot directly access the electronic health record (EHR) system. They also want to allow only authorized clinical devices to communicate with the EHR. Which security zone design best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.