Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 2

Zero Trust Endpoints GDSA Practice Questions (Page 10)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 46–50

  1. 46application · medium

    A company's security team wants to detect endpoints that are running unauthorized software, such as peer-to-peer file-sharing applications. The team has an endpoint detection and response (EDR) tool that collects process and file information. Which detection method is most effective?

    Select an answer first
  2. 47foundation · easy

    Why is it important to evaluate endpoint trust level before granting access in a zero trust model?

    Select an answer first
  3. 48expert · hard

    A large enterprise is implementing micro-segmentation for its data center. The security team has identified that the legacy 'finance' application tier can only be segmented using IP addresses and ports, as it does not support modern identity-aware tags. The team is concerned about the operational overhead of managing these rules. Which approach best balances security and operational efficiency?

    Select an answer first
  4. 49application · medium

    A law firm's remote-access policy allows partners to access case-management files from any device, but associates can only access them from firm-managed laptops. The identity provider (IdP) already knows the user's role and the device's compliance status. Which access-control model should the firm implement?

    Select an answer first
  5. 50expert · hard

    A global engineering firm has a zero trust architecture that uses a posture-check agent on all managed Windows laptops. The agent reports OS patch level, antivirus status, and disk encryption status to the access gateway. Recently, the firm acquired a small subsidiary that uses Linux laptops. The Linux laptops do not have the posture agent installed, and the IT team is concerned that these devices will be unable to access the corporate SaaS applications. The firm's security policy requires all endpoints to meet the same posture requirements before accessing any corporate resource. The IT team has a limited budget and needs a solution that can be implemented quickly. Which approach best satisfies the security policy while accommodating the Linux laptops?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GDSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.