Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 2

Zero Trust Endpoints GDSA Practice Questions (Page 7)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 31–35

  1. 31expert · hard

    A company's zero trust policy engine uses a risk score that combines user behavior, device posture, and data sensitivity. A user with a compliant device is accessing a low-sensitivity document repository. The user's behavior score drops because they are downloading an unusually large number of files. The policy engine must decide on an action. What is the most appropriate response that balances security and user productivity?

    Select an answer first
  2. 32application · medium

    A university allows students to access the library's online journal database from personal laptops. The IT department wants to grant access only when the device has an up-to-date antivirus and a non-admin user account. Which approach should the IT department take?

    Select an answer first
  3. 33foundation · easy

    Which of the following is an example of endpoint context used in access control decisions?

    Select an answer first
  4. 34expert · hard

    A security analyst is investigating an alert from the EDR system. The alert indicates that a user's endpoint has been communicating with a known command-and-control (C2) server. The zero trust architecture has already isolated the endpoint. What is the most critical next step for the analyst to take to understand the scope of the compromise?

    Select an answer first
  5. 35application · medium

    A financial services firm issues managed laptops to employees. The security team wants to ensure that only the firm's own laptops can authenticate to the corporate VPN, even if a user's password is stolen. Which mechanism should be added to the VPN authentication flow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.