Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defensible Security Architect

Domain 1Objective 3

Zero Trust Networking GDSA Practice Questions (Page 6)

Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
7concepts

Questions 26–30

  1. 26expert · hard

    A law firm is implementing Zero Trust networking. The security team wants to ensure that only partners can access the client document repository, and that access is only allowed from firm-managed laptops. The firm also requires that all access be logged for client confidentiality audits. Which combination of controls is most appropriate?

    Select an answer first
  2. 27application · medium

    A large enterprise is migrating to Zero Trust networking. The network team is concerned about disrupting legacy applications that rely on direct IP communication. Management wants to see quick wins but also wants to minimize risk. Which deployment strategy is most appropriate?

    Select an answer first
  3. 28expert · hard

    A global enterprise is implementing zero trust networking. They have a mix of managed and unmanaged devices, and some users are contractors. The security team wants to grant access to a sensitive application only to managed devices with up-to-date antivirus and to users with multi-factor authentication (MFA) enabled. They also want to ensure that data in transit is encrypted. Which policy should they configure at the policy enforcement point?

    Select an answer first
  4. 29application · medium

    A hospital is deploying a new patient-records application. The security team wants to ensure that only the application server can talk to the database server, and only on the database port. They also want to enforce that only authenticated users with a compliant device can reach the application server. Which two controls should they implement together?

    Select an answer first
  5. 30expert · hard

    A healthcare provider has deployed microsegmentation policies to restrict access to patient records. The security team is seeing an alert about a user who is accessing the records system from an unusual location, but the user's credentials are valid and the device posture is compliant. The team needs to determine whether this is a legitimate access or a potential compromise. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.