Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 2

Zero Trust Endpoints GDSA Practice Questions (Page 9)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    A government agency issues smartcards to employees for accessing classified systems. The agency wants to ensure that the smartcard is bound to a specific, trusted endpoint and cannot be used from an unapproved device. Which additional control should be implemented?

    Select an answer first
  2. 42application · medium

    A company's zero trust policy engine detects that an endpoint's antivirus definitions are out of date. The endpoint is currently accessing a low-risk file share. The security team wants to automatically remediate the issue without disrupting the user's work. What is the most appropriate automated response?

    Select an answer first
  3. 43foundation · easy

    What is the primary goal of micro-segmentation for endpoints?

    Select an answer first
  4. 44expert · hard

    A large enterprise has a zero trust architecture that monitors endpoint activities using an EDR tool. The SOC receives an alert that a user's laptop is making repeated connections to an unusual external IP address at 3:00 AM. The user is not logged in at that time. The SOC investigates and finds that the laptop is running a scheduled task that was created by an unknown process. The laptop's posture check shows that the antivirus is up-to-date and the OS is fully patched. Which action should the SOC take first?

    Select an answer first
  5. 45application · medium

    A cloud-based SaaS application is accessed by employees from both corporate laptops and personal phones. The security team wants to enforce a policy that grants full access from corporate laptops, but only read-only access from personal phones, and blocks access entirely if the phone is rooted. Which control should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.