Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 96 pages
Exam (elaborations)

SANS SEC530 Exam 2026 Questions With Verified Answers

Document preview thumbnail
Preview 4 out of 96 pages

SANS SEC530 Exam 2026 Questions With Verified Answers

Content preview

SANS SEC530 Exam 2026 Questions With Verified Answers
Defensible Security Architecture & Engineering | GIAC GDSA Preparation

200 Practice Questions | Multiple Choice with Answer Key & Explanations



Question 1

Zero Trust fundamentally assumes:

A) Internal networks are safe and trusted

B) Every access request must be verified regardless of location

C) VPNs are unnecessary for security

D) Firewalls protect everything by default



Answer: B



Explanation: Zero Trust requires verification for every user, device, and access request regardless of
network location. It operates on the principle of "never trust, always verify," eliminating implicit trust even
for internal traffic



Question 2

What is the primary goal of a defensible security architecture?

A) Compliance with industry regulations

B) Reducing the attack surface

C) Maximizing return on security investments

D) Ensuring user productivity



Answer: B



Explanation: Reducing the attack surface is central to defensible architecture, limiting opportunities for
attackers to exploit systems. While compliance and ROI are considerations, attack surface reduction is the
primary architectural goal .

,Question 3

Micro-segmentation primarily helps to:

A) Reduce network latency

B) Prevent lateral movement of attackers

C) Encrypt all traffic end-to-end

D) Simplify VLAN design



Answer: B



Explanation: Micro-segmentation isolates workloads and creates security boundaries that restrict an
attacker's ability to move laterally across the network if a system is compromised .



Question 4

Which architecture concept ensures that no single component failure results in total system failure?

A) Least privilege

B) Redundancy

C) Encryption

D) Segmentation



Answer: B



Explanation: Redundancy provides alternate paths, systems, or components in case of failure, increasing
system reliability and availability. This is a fundamental principle of resilient security architecture .



Question 5

In Zero Trust, conditional access evaluates:

A) Only passwords and credentials

B) Device state, user identity, and contextual factors

C) Network latency and bandwidth

,D) VLAN assignment and subnet



Answer: B



Explanation: Conditional access in Zero Trust evaluates multiple factors including device posture, user
identity, location, time of access, and behavioral analytics before granting access to resources .



Question 6

What is the purpose of network segmentation?

A) Improve user authentication speed

B) Limit lateral movement and contain breaches

C) Encrypt all data in transit

D) Accelerate network traffic routing



Answer: B



Explanation: Network segmentation creates security boundaries that restrict an attacker's ability to move
laterally across the network. If one segment is compromised, segmentation prevents or slows spread to
other segments .



Question 7

Which of the following best defines Zero Trust Architecture?

A) Trust all internal traffic by default

B) Avoid encrypting internal data for performance

C) Always verify, never trust

D) Deploy firewalls at every endpoint

, Answer: C



Explanation: Zero Trust means continuous verification of every access request regardless of network
location, assuming no implicit trust is granted based solely on network position .



Question 8

Which project documents common tactics, techniques, and procedures (TTPs) that advanced persistent
threat groups use against enterprise networks?

A) DEF3NSE

B) DET3CT

C) ATP&CK

D) MITRE ATT&CK



Answer: D



Explanation: The MITRE ATT&CK framework is a globally accessible knowledge base of adversary tactics
and techniques based on real-world observations. It is used for threat modeling and defense strategy
development .



Question 9

Which of the following is described by Lockheed Martin as a countermeasure action to the Cyber Kill
Chain?

A) Disrupt

B) Prevent

C) React

D) Remove



Answer: A



Explanation: The Lockheed Martin Cyber Kill Chain framework identifies "Disrupt" as a countermeasure
action. Disrupt aims to break the attacker's chain at various phases to prevent successful compromise .

Document information

Uploaded on
April 10, 2026
Number of pages
96
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$8.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
francisndungu1
5.0
(1)
Sold
7
Followers
0
Items
589
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions