
GIAC Defensible Security Architect
Domain 1Objective 2
Zero Trust Endpoints GDSA Practice Questions (Page 6)
Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 26–30
- 26
A defense contractor has a zero trust architecture that requires both user authentication and device authentication. The contractor issues laptops with TPM-bound certificates for device identity. A new requirement states that all access to classified systems must also require the user to be in a specific physical location (e.g., a secure facility). The contractor's identity provider (IdP) currently supports certificate-based device authentication and user multi-factor authentication (MFA). Which additional control should be implemented to meet the location requirement without weakening device identity?
Select an answer first - 27
In a zero trust architecture, what is the primary role of a zero trust endpoint?
Select an answer first - 28
A company is implementing micro-segmentation for its endpoints. The security team has created a policy that allows an endpoint to communicate only with the specific servers it needs. However, they are concerned about the operational overhead of maintaining these policies as the environment changes. What is the most effective way to manage this?
Select an answer first - 29
An organization is implementing device identity for its IoT sensors. These sensors are headless and cannot support a full EDR agent. The security team needs a way to authenticate these devices to the network and ensure they are not spoofed. Which approach is most suitable for establishing a strong device identity for these IoT sensors?
Select an answer first - 30
A manufacturing company's endpoint protection platform (EPP) detects that a machine on the factory floor has a known malware signature. The machine is running a critical production process that cannot be interrupted during the day. What is the most appropriate automated response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.