GIAC GDSA Certification Sample Questions

GDSA Dumps, GDSA PDF, GDSA VCE, GIAC Defensible Security Architect VCE, GIAC GDSA PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Defensible Security Architect (GDSA) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GDSA certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GDSA Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Defensible Security Architect (GDSA) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Defensible Security Architect exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GDSA Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GDSA Sample Questions:

01. An organization routes remote users through a full-tunnel VPN that encrypts all of their traffic back to the corporate edge. The security team observes that its inline intrusion detection sensor, which used to see this traffic, now reports almost nothing on the VPN users' sessions.
What best explains this and what is the appropriate response?
a) The VPN is misrouting traffic away from the sensor and the routing should be corrected
b) The encryption is optional overhead and should be disabled so the sensor can inspect the traffic in the clear again
c) Encryption blinds inline inspection, so terminate the tunnel at a controlled edge point and inspect it there
d) The sensor is failing, dropping packets, and undersized, so it should be replaced with an identical model
 
02. Operating under a presume-breach posture, a team wants a high-fidelity, low-false-positive tripwire that fires when an intruder harvests and reuses credentials while moving laterally.
Which control best provides that signal?
a) Add another firewall between segments to cut how many services an attacker can reach.
b) Require users to change their passwords more frequently so stolen credentials expire sooner.
c) Raise the logging level on every server across the whole estate and have the analysts read through the combined authentication logs together during the handover each morning.
d) Plant a canary credential no legitimate process ever uses, so any authentication attempt with it is a high-confidence sign of an intruder.
 
03. A review team is weighing the risk of the single jump box that brokers all administrative access into a critical zone. One member argues that concentrating every admin path through one host is dangerous because that host, if compromised, becomes a gateway inward to everything behind it.
What is the soundest way to treat this argument?
a) Accept the risk as real and manage it by hardening, monitoring, and tightly restricting the jump box
b) Dismiss it, because a jump box that enforces multi-factor authentication cannot be compromised
c) Accept it, abandon the jump box, remove the chokepoint, and let administrators connect directly to each server instead
d) Reframe it as an availability concern and solve it purely by clustering the jump box for redundancy
 
04. An architect must design administrative access for a small team of engineers who work remotely and need to reach the management interfaces of servers inside a highly sensitive zone. The design must authenticate the engineers strongly, funnel their sessions through one audited path, and prevent a connected session from ranging freely across the zone.
Which three elements together satisfy these requirements?
(Choose three.)
a) Expose each server's management interface directly to the internet behind a strong password
b) Grant a full tunnel that trusts the engineers' devices once they are inside the zone
c) Require two-factor authentication on the remote-access path the engineers use
d) Segment the zone and apply least privilege so a session reaches only the specific systems it needs
e) Route all administrative sessions through a hardened, monitored jump box that the servers alone accept connections from
 
05. Employees are tunneling a blocked file-sharing application over TCP 443 to evade the existing port-based firewall rules. Security needs to identify and block that specific application regardless of the port it uses.
Which control provides this?
a) Web application firewall.
b) Packet-filtering firewall.
c) Next-generation firewall.
d) Stateful firewall.
 
06. A proposal describes its remote-access authentication as two-factor because users must supply both a password and the answer to a preset security question before the VPN connects. A reviewer objects that this is not genuine two-factor authentication.
Why is the reviewer correct?
a) The security question must be encrypted in transit for the second factor to count
b) A password and a security answer are both knowledge factors, not two independent categories
c) Security questions are weaker passwords, but combining any two secrets still qualifies as two-factor
d) Two-factor requires two separate logins, two devices, and two sessions rather than two prompts in one login
 
07. A cloud tenant runs its web tier, application tier, and database tier in a single virtual network with no filtering between them. During an incident, a foothold on a web server was used to reach the database tier directly. Leadership asks which architectural change would most limit reach in a future compromise.
Which change best addresses the weakness this incident exposed?
a) Segment the tiers into zones with default-deny and permit only required flows
b) Turn on detailed flow logging and packet capture across the entire virtual network for later analysis
c) Enable full-disk encryption on the database tier's volumes
d) Require multi-factor authentication for administrators of the cloud console
 
08. Security wants all client web traffic to pass through a filtering proxy. They cannot rely on every browser being configured to use it, and they want the arrangement to be hard for users to bypass.
Which proxy deployment mode fits?
a) SMTP proxy.
b) Explicit proxy.
c) Reverse proxy.
d) Transparent proxy.
 
09. An organization is writing the baseline for securing its on-premise hypervisor hosts, which carry many production guests. Which three measures belong in that baseline?
(Choose three.)
a) Minimize the host's software footprint to a thin, purpose-built configuration with no general-purpose software
b) Isolate the hypervisor management interface and management network out-of-band from guest and user traffic
c) Patch the hypervisor promptly as critical infrastructure and tightly control who may administer it
d) Enable clipboard and shared-folder integration between every guest and the host for administrator convenience
e) Patch the hypervisor on the same relaxed schedule used for low-priority desktops
 
10. Administrators need to reach the management interfaces of servers in a restricted production zone. The security team wants every administrative session into that zone to pass through one hardened, heavily monitored host that records the sessions, and it wants the production servers to accept administrative connections only from that host.
Which design meets this requirement?
a) A forward web proxy through which administrators browse to the servers
b) A jump box the administrators connect through, which the servers alone accept admin connections from
c) Direct administrative access to each server, protected by strong passwords
d) A remote-access VPN that places administrators' devices directly onto the production zone's network segment

Answers:

Question: 01
Answer: c
Question: 02
Answer: d
Question: 03
Answer: a
Question: 04
Answer: c, d, e
Question: 05
Answer: c
Question: 06
Answer: b
Question: 07
Answer: a
Question: 08
Answer: d
Question: 09
Answer: a, b, c
Question: 10
Answer: b

Note: For any error in GIAC Defensible Security Architect (GDSA) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (76 votes)