Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 2

Zero Trust Endpoints GDSA Practice Questions (Page 5)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 21–25

  1. 21expert · hard

    An organization is implementing device authentication for its remote workforce. They are considering using certificate-based authentication (CBA) with a private CA. The security team is concerned about the scalability of managing certificates for thousands of devices. What is the most effective way to address this concern?

    Select an answer first
  2. 22foundation · easy

    What is the purpose of continuous posture and health checks for endpoints in a zero trust architecture?

    Select an answer first
  3. 23application · medium

    A security operations center (SOC) analyst is investigating a potential incident involving a laptop that was reported stolen. The zero trust architecture has already revoked the device's certificate and blocked its access to corporate resources. What additional endpoint monitoring and visibility action should the SOC take to understand the potential impact?

    Select an answer first
  4. 24application · medium

    An organization's zero trust policy engine dynamically adjusts access rights based on real-time risk signals. A user's endpoint is compliant, but the user is attempting to access a sensitive HR application from a new, unusual geographic location at an atypical time of day. The policy engine flags this as a risk. What is the most appropriate dynamic access control response?

    Select an answer first
  5. 25expert · hard

    A company's zero trust architecture uses automated remediation for non-compliant endpoints. When an endpoint fails a posture check (e.g., missing patch), the system automatically blocks access to corporate resources and sends a notification to the user. The company's security team wants to add a remediation workflow that allows the user to self-remediate the issue (e.g., install the patch) and regain access without IT intervention. Which approach best implements this workflow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.