
GIAC Defensible Security Architect
Domain 3Objective 2
Network Encryption and Remote Access GDSA Practice Questions (Page 1)
Part of the Network Services and Encryption domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 1–5
- 1
A security analyst is reviewing a TLS 1.2 configuration for a web server. The current cipher suite is TLS_RSA_WITH_AES_128_CBC_SHA. The analyst wants to enable forward secrecy to protect past sessions if the server's private key is compromised. Which change should be made?
Select an answer first - 2
A financial firm uses a hardware security module (HSM) to store the private keys for its TLS certificates. The certificates are used on multiple web servers. The security policy requires that the private keys never leave the HSM. How should the firm configure the web servers to use these keys?
Select an answer first - 3
What is the purpose of the TLS handshake?
Select an answer first - 4
What is the primary purpose of key rotation in an enterprise encryption key management program?
Select an answer first - 5
A large enterprise is migrating to a cloud-based KMS. The security team requires that the cloud provider cannot access the encryption keys. They also need to maintain the ability to encrypt and decrypt data in the cloud with low latency. Which architecture best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.