
GIAC Defensible Security Architect
Domain 1Objective 2
Zero Trust Endpoints GDSA Practice Questions (Page 8)
Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 36–40
- 36
How does network segmentation help protect endpoints in a zero trust architecture?
Select an answer first - 37
In a zero trust architecture, what factors are used to evaluate the trust level of an endpoint before granting access?
Select an answer first - 38
A company is designing a zero trust architecture for a hybrid environment with both on-premises and cloud workloads. They are defining the trust boundary for endpoints. Which approach aligns with the zero trust principle of 'never trust, always verify'?
Select an answer first - 39
A financial services firm requires all remote employees to use company-managed laptops. The security team needs to ensure that only endpoints with the latest OS patches, active antivirus, and enabled disk encryption can access the corporate SaaS applications. The solution must evaluate these attributes at the time of each access request and block access if any are missing. Which approach best meets this requirement?
Select an answer first - 40
Which mechanism is commonly used to establish a strong device identity for an endpoint in a zero trust architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.