GIAC GDSA Exam Overview:
| Certification Vendor: | GIAC (SANS Institute) |
|---|---|
| Exam Name: | GIAC Defensible Security Architect (GDSA) |
| Exam Number: | GDSA |
| Exam Duration: | 180 minutes |
| Available Languages: | English |
| Related Certifications: | SANS SEC530 GIAC GCED GIAC GCIA GIAC GCIH GIAC GSEC |
| Passing Score: | 73% |
| Real Exam Qty: | 115 |
| Exam Format: | Proctored, Open Book, Multiple Choice |
| Exam Price: | $979 USD |
| Certificate Validity Period: | 4 years |
| Recommended Training: | SANS SEC530: Defensible Security Architecture |
| Exam Registration: | GIAC Certification Registration |
| Sample Questions: | GIAC GDSA Sample Questions |
| Exam Way: | Online proctored exam (remote proctoring or authorized testing delivery depending on GIAC policies) |
| Pre Condition: | No formal prerequisites required. Recommended 3–5 years of experience in security architecture or enterprise security engineering. |
| Official Syllabus URL: | https://www.giac.org/certifications/defensible-security-architect-gdsa/ |
GIAC GDSA Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Enterprise Security Architecture | - Enterprise security controls design - Defense-in-depth strategies |
| Risk Management and Governance | - Security governance and compliance - Risk assessment methodologies |
| Security Architecture Foundations | - Architecture frameworks and models - Security design principles |
| Cloud and Hybrid Security Architecture | - Cloud shared responsibility model - Secure cloud infrastructure design |
| Network Security Architecture | - Segmentation and zoning - Secure network design principles |
| Identity and Access Management (IAM) | - Authentication and authorization architecture - Privileged access management |
GIAC Defensible Security Architect Sample Questions:
What is a key characteristic of the Zero Trust Model?
Response:
- A. Trust is never assumed and must be continually verified
- B. Unlimited access within the network perimeter
- C. Trust is based on the network perimeter
- D. Relies solely on external threat intelligence
Correct Answer: A 🗳️
What is the primary security feature that 802.1X provides for network access?
Response:
- A. Increased data transmission speed
- B. Encryption of data traffic
- C. Bandwidth management
- D. Access control through authentication
Correct Answer: D 🗳️
Which of the following is a recommended mitigation for IPv6 router advertisement attacks?
Response:
- A. Disabling all IPv6 traffic on the network
- B. Increasing the number of subnets in the network
- C. Enabling router advertisement protection features on network devices
- D. Enabling MAC address filtering
Correct Answer: C 🗳️
Which of the following strategies are effective for securing Zero Trust endpoints?
(Choose two)
Response:
- A. Allowing unrestricted access to network resources
- B. Relying solely on traditional perimeter defense
- C. Enforcing multi-factor authentication (MFA) for all users
- D. Hardening endpoints by disabling unused services
Correct Answer: C,D 🗳️
In a Zero Trust Networking model, what is the primary role of Single Packet Authentication (SPA)?
Response:
- A. Encrypting data at rest
- B. Monitoring user behavior across the network
- C. Verifying and authenticating a device before allowing network access
- D. Reducing the number of available IP addresses
Correct Answer: C 🗳️
We're so confident of our products that we provide no hassle product exchange.


By Victoria

