Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 1

Zero Trust Fundamentals GDSA Practice Questions (Page 8)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 36–40

  1. 36expert · hard

    A security architect is designing a Zero Trust network for a research lab. The lab has a mix of managed and unmanaged devices (e.g., personal laptops of visiting researchers). The architect needs to allow these unmanaged devices to access a specific collaboration server while preventing access to sensitive research data. Which approach best meets this requirement?

    Select an answer first
  2. 37expert · hard

    A security team is implementing Zero Trust for a cloud-native application. The application consists of multiple microservices that communicate with each other. The team wants to enforce least privilege and verify every service-to-service request. Which approach is most aligned with Zero Trust principles?

    Select an answer first
  3. 38application · medium

    An organization wants to implement Zero Trust for remote workers who access a specific set of cloud applications. They want to avoid exposing the applications to the public internet and want to enforce access based on user identity and device posture. Which deployment model best fits this requirement?

    Select an answer first
  4. 39expert · hard

    A security architect is proposing a Zero Trust architecture to the board. The board is concerned about the cost and complexity of implementation. Which argument best justifies the investment?

    Select an answer first
  5. 40expert · hard

    A company has a Zero Trust architecture that uses micro-segmentation. A new application needs to communicate with a database on a different segment. The security team is unsure which ports are required. What is the best approach to maintain Zero Trust while enabling the application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.