
GIAC Defensible Security Architect
Domain 1Objective 3
Zero Trust Networking GDSA Practice Questions (Page 9)
Part of the Zero Trust Architecture domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 41–45
- 41
A financial services firm is implementing zero trust networking for its internal microservices. The services communicate over HTTP on an internal network. The security team wants to ensure that only authenticated services can call each other and that the traffic is protected from eavesdropping. Which approach should they choose?
Select an answer first - 42
A company is redesigning its network to adopt Zero Trust principles. The security team wants to ensure that a user's access to an internal application is not automatically trusted just because the user is on the corporate network. Which policy change is most aligned with Zero Trust?
Select an answer first - 43
A hospital is deploying a Zero Trust network. The compliance team requires that only the cardiology department's workstations can reach the cardiology EHR application, and only during scheduled shifts. The network team wants to avoid creating separate VLANs for every department. Which approach best meets the requirement?
Select an answer first - 44
A company is redesigning its network security architecture. The CISO wants to move away from the traditional model where being on the internal network implies trust. Instead, they want every access request to be authenticated, authorized, and encrypted, regardless of the user's location. Which architecture change best aligns with this goal?
Select an answer first - 45
A company is evaluating zero trust networking solutions. They have a requirement that all access decisions must consider the user's role, the device's compliance status, and the sensitivity of the data being accessed. They also want to avoid a single point of failure in the enforcement path. Which architecture best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.