GIAC GDSA Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Defensible Security Architect |
| Exam Number: | GDSA |
| Real Exam Qty: | 75 |
| Exam Format: | Web-Based Proctored Exam, Multiple Choice |
| Related Certifications: | GIAC Defensible Security Architect Certification |
| Passing Score: | 63% |
| Exam Duration: | 120 minutes |
| Exam Price: | $999 USD |
| Certificate Validity Period: | 4 Years |
| Available Languages: | English |
| Sample Questions: | GIAC GDSA Sample Questions |
| Exam Way: | Online remote proctored or onsite testing through Pearson VUE. |
| Pre Condition: | No formal prerequisite. SEC530: Defensible Security Architecture and Engineering training is recommended. |
| Official Syllabus URL: | https://www.giac.org/certifications/defensible-security-architecture-gdsa/ |
GIAC GDSA Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Zero Trust Networking | - Network Architecture
|
| Topic 2: Fundamental Layer 3 Defense | - IP Network Security
|
| Topic 3: Layer 1 and Layer 2 Defense | - Network Infrastructure Security
|
| Topic 4: Data Discovery, Governance, and Mobility Management | - Data Governance
|
| Topic 5: Data-Centric Security | - Data Protection
|
| Topic 6: Network Proxies and Firewalls | - Perimeter Security
|
| Topic 7: Zero Trust Fundamentals | - Zero Trust Principles
|
| Topic 8: Zero Trust Endpoints | - Endpoint Protection
|
| Topic 9: Network Defenses | - Threat Mitigation
|
| Topic 10: Cloud-based Security Architecture | - Cloud Security Concepts
|
| Topic 11: IPv6 | - IPv6 Security
|
| Topic 12: Network Encryption and Remote Access | - Secure Connectivity
|
| Topic 13: Fundamental Security Architecture Concepts | - Architecture Principles
|
GIAC Defensible Security Architect Sample Questions:
What are some proactive defenses used in Zero Trust Networking to change attacker behaviors?
(Choose two)
Response:
- A. Providing attackers with unrestricted access to low-value systems
- B. Using red herring defenses to mislead attackers
- C. Reducing monitoring activities to save bandwidth
- D. Implementing honeypots to attract and monitor malicious activity
Your organization has implemented a Zero Trust architecture to enhance network security. However, several systems are still relying on traditional perimeter defenses, which have become ineffective against advanced threats. To comply with the Zero Trust model, what immediate actions should your team prioritize to protect the organization's critical assets?
Response:
- A. Upgrade perimeter firewalls and focus on reducing network traffic
- B. Implement micro-segmentation, enforce strong identity verification, and adopt the principle of least privilege
- C. Disable all access to internal systems and require manual approvals for every request
- D. Decrease logging activities to focus on higher-priority events only
What is the primary function of Host Intrusion Detection Systems (HIDS) in endpoint security?
Response:
- A. Detecting and alerting on potential threats and unauthorized changes to the endpoint
- B. Monitoring network traffic for suspicious activity
- C. Managing user authentication across the network
- D. Encrypting data at rest on the endpoint
Your organization is implementing a Zero Trust model, and part of the strategy involves hardening all endpoints. You notice that several employee laptops are not receiving critical security updates, which could expose the organization to potential threats. What immediate steps should you take to secure the endpoints and ensure they comply with the Zero Trust strategy?
Response:
- A. Automate the patching process for all endpoints and enforce multi-factor authentication (MFA) for all users
- B. Manually install patches on each laptop and restrict user access to the network
- C. Disable all network access until the endpoints are updated
- D. Allow users to update their devices when they are available and review the process after three months
In the Diamond Model of Intrusion Analysis, which of the following elements does NOT belong?
Response:
- A. Adversary
- B. Capability
- C. Infrastructure
- D. Return on Investment
We're so confident of our products that we provide no hassle product exchange.


By Quintina

