Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Defensible Security Architect

Defensible Security Architect

The GIAC Defensible Security Architect (GDSA) certification validates your ability to architect comprehensive defenses that balance prevention, detection, and response. It is designed for security architects, network engineers, and senior security professionals who design and implement layered, network-centric and data-centric controls. Earning GDSA proves you can apply Zero Trust principles and build defense-in-depth that is maintainable and effective.

Exam formatMultiple choice
Duration120 minutes
DeliveryGIAC
Passing score63%
Free questions602

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Defensible Security Architect proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

5domains
13objectives
108concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Defensible Security Architect (GDSA) certification validates a practitioner's ability to architect comprehensive defenses that balance prevention, detection, and response capabilities. GDSA certification holders are qualified to design and implement a strategic combination of network-centric and data-centric controls that create defense in depth.

The certification covers using network-centric and data-centric security strategies to architect a layered defense, assessing existing technology implementations to improve prevention, detection, and response, and understanding and applying Zero Trust principles. GDSA holders are versatile blue-teamers and cyber defenders with an arsenal of skills to protect an organization's critical data, from the endpoint to the cloud, across networks and applications.

Who it’s for

The GDSA certification is for security architects, network engineers, network architects, security analysts, senior security engineers, system administrators, technical security managers, CND analysts, security monitoring specialists, and cyber threat investigators. It is ideal for professionals who are responsible for designing and implementing enterprise defenses, and who need to balance prevention, detection, and response capabilities across network and data-centric controls.

Recommended experience

Practical work experience in security architecture, network defense, and implementing security controls is recommended to master the skills necessary for certification. Hands-on experience designing and implementing network-centric and data-centric security controls; Familiarity with Zero Trust principles and applying them to enterprise architectures; Understanding of network protocols, firewalls, proxies, and endpoint security; Experience with cloud security concepts and container security

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Zero Trust Architecture
  • Zero Trust Fundamentals
  • Zero Trust Endpoints
  • Zero Trust Networking
3 objectives · 146 free questions · 30 pages
Network Security Fundamentals
  • Fundamental Security Architecture Concepts
  • Fundamental Layer 3 Defense
  • Layer 1/Layer 2 Defense
  • Network Defenses
4 objectives · 148 free questions · 31 pages
Network Services and Encryption
  • Network Proxies and Firewalls
  • Network Encryption and Remote Access
  • IPv6
3 objectives · 140 free questions · 29 pages
Data Protection and Governance
  • Data-Centric Security
  • Data Discovery, Governance, and Mobility Management
2 objectives · 106 free questions · 22 pages
Cloud Security Architecture
  • Cloud-based Security Architecture
1 objectives · 62 free questions · 13 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Defensible Security Architect
Exam formatMultiple choice
Duration120 minutes
Questions75 questions
Passing score63%
DeliveryGIAC
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Defensible Security Architect

GIAC Defensible Security Architect badgeCredential earnedGIAC Defensible Security Architect Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the GDSA exam relate to the retired version released before August 3, 2019?

The passing score for the GDSA exam is 63% for all candidates who receive the exam version released on or after August 3, 2019. To confirm the exam format and passing score that apply to your specific attempt, refer to the Certification Information section of your GIAC account.

Is there a hands-on or lab component in the GDSA exam?

The GDSA exam is a proctored, web-based exam with 75 questions. It does not include a hands-on lab component; it is a multiple-choice exam.

What are the proctoring options for the GDSA exam?

All GIAC Certification exams are web-based and required to be proctored. There are two proctoring options: remote proctoring through ProctorU, and onsite proctoring through PearsonVUE.

How long do I have to complete my GDSA certification attempt after activation?

You will have 120 days from the date of activation to complete your certification attempt.

What job roles does the GDSA certification map to?

The GDSA certification is designed for security architects, network engineers, network architects, security analysts, senior security engineers, system administrators, technical security managers, CND analysts, security monitoring specialists, and cyber threat investigators.

Can I renew my GDSA certification by passing a different GIAC exam?

GIAC certifications can be renewed by retaking the same exam or by earning 36 CPE credits over four years. Passing a different GIAC exam may count toward CPE credits, but it does not automatically renew the GDSA certification.

Are there any regional restrictions for taking the GDSA exam?

GIAC offers remote proctoring through ProctorU and onsite proctoring through PearsonVUE, which are available in many regions worldwide. Check with GIAC for specific regional availability.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 602 questions, free, no account needed.