
GIAC Defensible Security Architect
Domain 1Objective 3
Zero Trust Networking GDSA Practice Questions (Page 3)
Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 11–15
- 11
How does mutual TLS (mTLS) differ from standard TLS in a Zero Trust environment?
Select an answer first - 12
Which security benefit is most directly achieved by implementing microsegmentation?
Select an answer first - 13
A company is moving from a traditional perimeter-based security model to Zero Trust. The CISO wants to ensure that access decisions are based on the user's identity and device posture, not just the source IP address. Which architectural change is most aligned with this goal?
Select an answer first - 14
What is the primary purpose of microsegmentation in a Zero Trust network?
Select an answer first - 15
What is a common recommended approach for deploying Zero Trust Networking in an existing enterprise environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.