SANS - SEC530 UPDATED EXAM QUESTIONS
AND CORRECT ANSWERS
SANS SEC530: Defensible Security Architecture & Engineering
Comprehensive Practice Exam (Original Questions + Answers)
Domain 1: Zero Trust Architecture
Question 1
An organization wants to implement Zero Trust principles.
Which approach BEST aligns with Zero Trust architecture?
A. Trust all internal network users because they are behind the
firewall
B. Authenticate users once and allow unrestricted lateral
movement
C. Continuously verify identity, device posture, and access
context
D. Remove all perimeter firewalls and rely only on endpoint
antivirus
Correct Answer: C
Explanation:
Zero Trust assumes no implicit trust. Access decisions should
consider identity, device health, location, risk, and requested
resources.
,Question 2
Which component is responsible for making the access decision in
a Zero Trust architecture?
A. Policy Enforcement Point (PEP)
B. Policy Decision Point (PDP)
C. Network Interface Card (NIC)
D. Security Information and Event Management (SIEM)
Correct Answer: B
Explanation:
The PDP evaluates policies and determines whether access
should be granted. The PEP enforces that decision.
Question 3
A company wants administrators to access production servers
only when needed and only for the duration required. Which
control is BEST?
A. Permanent administrator accounts
B. Shared privileged accounts
C. Just-in-time privileged access
D. Disable logging for administrators
Correct Answer: C
Domain 2: Network Segmentation and Architecture
Question 4
, A security architect wants to limit east-west traffic between
workloads inside a data center. Which solution is MOST
effective?
A. Increasing internet bandwidth
B. Microsegmentation
C. Removing VLANs
D. Disabling routing
Correct Answer: B
Explanation:
Microsegmentation limits lateral movement by applying granular
access controls between workloads.
Question 5
Which technology is commonly used to separate Layer 2
broadcast domains?
A. VLANs
B. NAT
C. TLS
D. DNSSEC
Correct Answer: A
Question 6
A company places public web servers in a separate network
segment from internal databases. This design is an example of:
AND CORRECT ANSWERS
SANS SEC530: Defensible Security Architecture & Engineering
Comprehensive Practice Exam (Original Questions + Answers)
Domain 1: Zero Trust Architecture
Question 1
An organization wants to implement Zero Trust principles.
Which approach BEST aligns with Zero Trust architecture?
A. Trust all internal network users because they are behind the
firewall
B. Authenticate users once and allow unrestricted lateral
movement
C. Continuously verify identity, device posture, and access
context
D. Remove all perimeter firewalls and rely only on endpoint
antivirus
Correct Answer: C
Explanation:
Zero Trust assumes no implicit trust. Access decisions should
consider identity, device health, location, risk, and requested
resources.
,Question 2
Which component is responsible for making the access decision in
a Zero Trust architecture?
A. Policy Enforcement Point (PEP)
B. Policy Decision Point (PDP)
C. Network Interface Card (NIC)
D. Security Information and Event Management (SIEM)
Correct Answer: B
Explanation:
The PDP evaluates policies and determines whether access
should be granted. The PEP enforces that decision.
Question 3
A company wants administrators to access production servers
only when needed and only for the duration required. Which
control is BEST?
A. Permanent administrator accounts
B. Shared privileged accounts
C. Just-in-time privileged access
D. Disable logging for administrators
Correct Answer: C
Domain 2: Network Segmentation and Architecture
Question 4
, A security architect wants to limit east-west traffic between
workloads inside a data center. Which solution is MOST
effective?
A. Increasing internet bandwidth
B. Microsegmentation
C. Removing VLANs
D. Disabling routing
Correct Answer: B
Explanation:
Microsegmentation limits lateral movement by applying granular
access controls between workloads.
Question 5
Which technology is commonly used to separate Layer 2
broadcast domains?
A. VLANs
B. NAT
C. TLS
D. DNSSEC
Correct Answer: A
Question 6
A company places public web servers in a separate network
segment from internal databases. This design is an example of: