Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 39 páginas
Examen

SANS SEC530: DEFENSIBLE SECURITY ARCHITECTURE AND ENGINEERING EXAM 2026- QUESTIONS LATEST 2026 – 2027 VERSION SOLVED QUESTIONS & ANSWERS

Document preview thumbnail
Vista previa 4 fuera de 39 páginas

SANS SEC530: DEFENSIBLE SECURITY ARCHITECTURE AND ENGINEERING EXAM 2026- QUESTIONS LATEST 2026 – 2027 VERSION SOLVED QUESTIONS & ANSWERS

Vista previa del contenido

Page 1 of 39


SANS SEC530: DEFENSIBLE SECURITY ARCHITECTURE AND
ENGINEERING EXAM 2026- QUESTIONS LATEST 2026 – 2027
VERSION SOLVED QUESTIONS & ANSWERS




SANS SEC530: Defensible Security Architecture and Engineering

250 Practice Exam Questions with Detailed Rationales



DOMAIN 1: DEFENSIBLE SECURITY ARCHITECTURE FUNDAMENTALS (Questions 1-
50)

1. Which of the following best defines "Defensible Security Architecture" as a core
concept that underpins the entire SEC530 framework for designing resilient
enterprise security systems?

A) A security model that focuses solely on strengthening the traditional network
perimeter to prevent all external attacks
B) A framework that assumes breaches will inevitably occur and therefore focuses on
building systems that can detect intrusions, respond effectively, and minimize damage
C) An architecture that relies entirely on signature-based detection mechanisms to
identify known threats before they can cause harm
D) A model that eliminates all system vulnerabilities through rigorous pre-deployment
testing and validation processes
E) A system that focuses exclusively on endpoint protection and ignores network-level
security controls

Correct Answer: B - Defensible Security Architecture acknowledges that no system is
perfectly secure and that breaches are inevitable. It emphasizes building systems that
can detect intrusions, respond effectively, and minimize damage—rather than
assuming a perfect perimeter can prevent all attacks . This philosophy shifts the focus
from prevention alone to a balanced approach incorporating detection and response
capabilities.

, Page 2 of 39




2. The DARIOM lifecycle in defensible security architecture encompasses which of
the following phases that guide the continuous improvement of security controls
and system resilience?

A) Discover, Assess, Remediate, Implement, Operate, Monitor
B) Design, Assess, Respond, Improve, Operate, Manage
C) Define, Architect, Review, Implement, Operate, Maintain
D) Discover, Assess, Remediate, Improve, Operate, Measure
E) Define, Analyze, Respond, Improve, Optimize, Monitor

Correct Answer: A - The DARIOM lifecycle stands for Discover, Assess, Remediate,
Implement, Operate, and Monitor. This framework guides security architects through a
continuous cycle of identifying assets and threats, assessing vulnerabilities,
implementing controls, and maintaining ongoing monitoring .



3. According to the Time-Based Security model, which of the following
mathematical relationships must hold true for an organization to achieve effective
security against a determined adversary?

A) Protection Time (P) must be less than Detection Time (D) plus Response Time (R)
B) Protection Time (P) must be greater than Detection Time (D) plus Response Time (R)
C) Protection Time (P) must equal Detection Time (D) plus Response Time (R)
D) Detection Time (D) must be greater than Protection Time (P) plus Response Time (R)
E) Response Time (R) must be greater than Protection Time (P) plus Detection Time (D)

Correct Answer: B - The Time-Based Security model states that for effective security,
the time a system can be protected (P) must be greater than the sum of detection time
(D) and response time (R). Mathematically, P > D + R. This means the organization must
be able to detect and respond to threats before the protection mechanisms fail .



4. The term "breakout point" in the context of a cyber attack timeline refers to
which critical moment that security architects must focus on detecting and
preventing?

A) The moment when an attacker first gains initial access to the network through a
phishing email or vulnerable service
B) The point in the attack when lateral movement first occurs, signaling that the attacker
is moving from the initial compromised host to other systems
C) The point when an attacker successfully exfiltrates sensitive data from the
organization's network

, Page 3 of 39


D) The moment when an attacker deploys ransomware and begins encrypting critical
files
E) The point when the attacker's command-and-control communication is first
established

Correct Answer: B - The breakout point is when lateral movement first occurs, signaling
the time when the attack moves beyond the initial compromised system to other
computers. This is when the attack becomes exponentially more dangerous and is a
critical point for detection and containment .



5. Which of the following countermeasures, as defined by the Cyber Kill Chain
framework, is intended to disrupt an attacker's ability to weaponize their exploits
and deliver malicious payloads to target systems?

A) Detect (identifying reconnaissance activities)
B) Deny (preventing the delivery of exploits)
C) Disrupt (interrupting command and control communications)
D) Degrade (reducing the effectiveness of the attack)
E) Deceive (misleading the attacker about the environment)

Correct Answer: B - The Cyber Kill Chain countermeasures include Detect, Deny,
Disrupt, Degrade, and Deceive. Deny is the countermeasure focused on preventing the
delivery of weaponized exploits to target systems, making it more difficult for attackers
to successfully execute their attack .



6. The OODA Loop, originally developed for military strategy, is applied in
cybersecurity to emphasize which of the following principles for maintaining an
effective defensive posture against evolving threats?

A) The organization should focus on having the most advanced prevention controls to
eliminate all threats
B) The organization must cycle through Observe, Orient, Decide, and Act faster than the
adversary can adapt
C) The organization should prioritize compliance with regulatory frameworks over
operational agility
D) The organization should rely on static security controls that require minimal
maintenance
E) The organization should focus exclusively on detection capabilities and ignore
prevention

Correct Answer: B - The OODA Loop (Observe, Orient, Decide, Act) is a decision-
making framework that emphasizes the importance of cycling through observation,

, Page 4 of 39


orientation, decision-making, and action faster than an adversary can adapt. This
allows defenders to make decisions at the speed of the adversary and maintain an
advantage .



7. What is the primary purpose of threat modeling using frameworks such as MITRE
ATT&CK in the context of defensible security architecture?

A) To create a comprehensive inventory of all potential vulnerabilities in the
organization's systems
B) To document all past security incidents for regulatory reporting and compliance
requirements
C) To understand adversary behaviors, identify defensive gaps, and prioritize security
controls based on real-world threats
D) To replace the need for penetration testing and vulnerability scanning programs
E) To assign blame and accountability for security failures to specific individuals or
departments

Correct Answer: C - Threat modeling with MITRE ATT&CK helps security architects
understand adversary behaviors, identify defensive gaps, and prioritize controls based
on real-world threats. It provides a common language for discussing threats and
enables more effective defensive design .



8. The principle of "defense-in-depth" differs from "defensible security
architecture" in which of the following fundamental ways that a security architect
must understand for effective system design?

A) Defense-in-depth focuses exclusively on network perimeter controls, while
defensible architecture focuses on endpoint protection
B) Defense-in-depth is a strategy of layering multiple security controls, while defensible
architecture emphasizes that breaches will occur and focuses on detection and
response
C) Defense-in-depth is obsolete and has been replaced entirely by Zero Trust models
D) Defense-in-depth is only applicable to physical security, not cybersecurity
E) Defense-in-depth and defensible architecture are identical concepts with no
meaningful distinction

Correct Answer: B - Defense-in-depth is the strategy of layering multiple, overlapping
security controls to provide redundancy. Defensible security architecture builds on this
by acknowledging that even layered defenses will eventually be breached, so the
architecture must be designed for effective detection, response, and recovery .

Información del documento

Subido en
24 de agosto de 2026
Número de páginas
39
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$13.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
NURSEJON
4.0
(2)
Vendido
17
Seguidores
1
Artículos
4236
Última venta
1 día hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes