
GIAC Defensible Security Architect
Domain 3Objective 1
Network Proxies and Firewalls GDSA Practice Questions (Page 3)
Part of the Network Services and Encryption domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 11–15
- 11
A company is deploying a reverse proxy to protect a web application. They want to offload TLS termination to the proxy and also perform content inspection. However, they are concerned about the proxy becoming a single point of failure. Which approach best addresses both the security and availability requirements?
Select an answer first - 12
A security analyst notices that the firewall logs show many outbound connections from an internal host to a known command-and-control IP on TCP 443. The firewall is a stateful firewall. Which action is most appropriate to stop the communication?
Select an answer first - 13
What is the primary role of a network proxy in a client-server architecture?
Select an answer first - 14
In a layered defense, what is a benefit of placing a proxy in front of a firewall?
Select an answer first - 15
A company is designing a defense-in-depth architecture for a public web application. They have a limited budget and must choose between a WAF reverse proxy and a next-generation firewall (NGFW) with application inspection. The application is critical and must remain available. Which approach best balances security and availability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.