Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 2Objective 3

Layer 1/Layer 2 Defense GDSA Practice Questions (Page 2)

Part of the Network Security Fundamentals domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts

Questions 6–10

  1. 6application · medium

    A data center manager is concerned about unauthorized physical access to network switches in a shared colocation facility. The facility provides locked cabinets, but the manager wants an additional control that can detect if someone opens the cabinet or tampers with the equipment. Which control is most appropriate?

    Select an answer first
  2. 7application · medium

    A small business has a network closet that is accessible to all employees. The owner wants to prevent someone from unplugging a switch and plugging in a personal device to gain network access. Which combination of physical and Layer 2 controls is most effective?

    Select an answer first
  3. 8expert · hard

    A network administrator is investigating a security incident where an attacker on a guest VLAN was able to intercept traffic from a user on a different VLAN. The attacker used a double-tagged 802.1Q frame to send traffic to the victim's VLAN. The switch is configured with the default native VLAN on trunk ports. Which configuration change would best mitigate this type of VLAN hopping attack?

    Select an answer first
  4. 9application · medium

    A security analyst is investigating a report of slow network performance. The analyst discovers that an attacker has been sending frames with 802.1Q tags and a native VLAN mismatch to reach a VLAN that should be isolated. Which Layer 2 attack is being used, and which mitigation is most effective?

    Select an answer first
  5. 10application · medium

    A small financial firm occupies a shared office building. The server room door has a standard key lock, and the network rack is open to the hallway. A recent audit noted that an unauthorized person could unplug a switch uplink and plug in a rogue device. Which combination of controls would best address the physical exposure while also limiting the impact of a rogue device at the data link layer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.