Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 3

Zero Trust Networking GDSA Practice Questions (Page 2)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
7concepts

Questions 6–10

  1. 6expert · hard

    A multinational corporation is deploying a Zero Trust network. The security team wants to enforce that only users with a specific clearance level can access a sensitive application, and that the access is encrypted. The application is hosted in a private cloud, and users access it from both corporate and personal devices. Which policy enforcement point configuration is most appropriate?

    Select an answer first
  2. 7application · medium

    A financial services firm is replacing its legacy VPN with a Zero Trust network. Remote employees must access only the specific internal applications their role requires, and the connection must be encrypted. Which combination of controls should the architecture include?

    Select an answer first
  3. 8application · medium

    A multi-tenant SaaS provider wants to ensure that tenants cannot access each other's backend databases. The databases are on the same network segment. The security team wants to enforce isolation at the network layer and also gain visibility into any cross-tenant traffic attempts. Which solution should they implement?

    Select an answer first
  4. 9foundation · easy

    Which activity is an example of using network visibility and analytics to enforce Zero Trust policies?

    Select an answer first
  5. 10application · medium

    A healthcare organization is implementing Zero Trust microsegmentation between its patient portal and the electronic health record (EHR) system. The security team requires that the EHR system verify the identity of the patient portal before accepting any requests, and that all data in transit be encrypted. Which mechanism should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.