Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 2

Zero Trust Endpoints GDSA Practice Questions (Page 2)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 6–10

  1. 6expert · hard

    A financial institution has a zero trust architecture that uses micro-segmentation to protect its trading application. The application consists of a web front-end, an application server, and a database. The security team wants to implement micro-segmentation to limit lateral movement, but the application has a legacy dependency: the application server must communicate with the database on a non-standard port, and the database must communicate with a third-party market-data feed on an external IP. The team is concerned that overly strict segmentation will break the application. Which approach best balances security and functionality?

    Select an answer first
  2. 7application · medium

    A company is implementing micro-segmentation for its server endpoints. The goal is to limit lateral movement if a web server is compromised. The security team has identified that the web server only needs to communicate with the application server on TCP 8080, and the application server only needs to communicate with the database server on TCP 1433. Which policy should be implemented?

    Select an answer first
  3. 8foundation · easy

    What is the purpose of using device identity in endpoint authentication?

    Select an answer first
  4. 9expert · hard

    A company's zero trust policy engine detects that an endpoint is non-compliant because it is missing critical security patches. The endpoint is used by a senior executive who is about to give a critical presentation to a client. The access policy is set to 'deny' for non-compliant devices. The executive's assistant requests an exception. What is the most appropriate action for the security team?

    Select an answer first
  5. 10application · medium

    A retail company's security operations center (SOC) wants to detect endpoints that are beaconing to a known command-and-control (C2) domain. The company uses a security information and event management (SIEM) platform that ingests endpoint logs. Which data source and detection method would provide the most direct visibility?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.