
GIAC Defensible Security Architect
Domain 3Objective 1
Network Proxies and Firewalls GDSA Practice Questions (Page 8)
Part of the Network Services and Encryption domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 36–40
- 36
Which firewall rule design practice best supports the principle of least privilege?
Select an answer first - 37
A security team is investigating a breach that involved an internal user accessing a malicious website. The proxy logs show the user's IP and the URL, but the team needs to identify the specific user and the content of the HTTPS request. Which additional logging or configuration would provide the most useful evidence?
Select an answer first - 38
An incident responder needs to investigate a suspected data exfiltration via HTTPS. The organization uses a forward proxy that terminates TLS. Which logging/inspection capability is most essential to see the actual content of the HTTPS sessions?
Select an answer first - 39
Why is logging of proxy and firewall traffic important for incident response?
Select an answer first - 40
A security architect is designing a defense-in-depth strategy. They have a firewall that performs stateful inspection and a proxy that performs URL filtering. They want to add a control that can detect and block malware that evades both the firewall and the proxy by using encrypted tunnels. Which control would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.