Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 3

Zero Trust Networking GDSA Practice Questions (Page 1)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
7concepts

Questions 1–5

  1. 1application · medium

    A university is implementing Zero Trust for its research network. The policy team wants to enforce access based on the researcher's identity, the security posture of their laptop, and the sensitivity of the data being accessed. Which component should make the final allow/deny decision?

    Select an answer first
  2. 2expert · hard

    A large enterprise is planning a Zero Trust network migration. The network team has identified that the legacy ERP system cannot support modern authentication protocols and relies on IP-based trust. The security team wants to enforce microsegmentation, but the ERP system must continue to function. Which approach is most appropriate?

    Select an answer first
  3. 3expert · hard

    A company is migrating to zero trust networking. They have a legacy application that cannot support modern authentication protocols and relies on IP-based access control. The migration team wants to integrate this application into the zero trust architecture without exposing it to the broader network. Which approach should they take?

    Select an answer first
  4. 4expert · hard

    A company is implementing zero trust networking and wants to protect data in transit between users and applications. They have a mix of web-based applications and legacy client-server applications that do not support TLS. The security team wants to ensure that all traffic is encrypted without requiring changes to the legacy applications. Which approach should they use?

    Select an answer first
  5. 5expert · hard

    A security architect is designing microsegmentation for a three-tier application (web, app, database). The web tier must be accessible from the internet, the app tier only from the web tier, and the database tier only from the app tier. The architect also wants to detect any attempt to bypass these rules. Which approach should they take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.