Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 39 pages
Exam (elaborations)

SANS SEC530: DEFENSIBLE SECURITY ARCHITECTURE AND ENGINEERING EXAM 2026- QUESTIONS LATEST 2026 – 2027 VERSION SOLVED QUESTIONS & ANSWERS

Document preview thumbnail
Preview 4 out of 39 pages

SANS SEC530: DEFENSIBLE SECURITY ARCHITECTURE AND ENGINEERING EXAM 2026- QUESTIONS LATEST 2026 – 2027 VERSION SOLVED QUESTIONS & ANSWERS

Content preview

Page 1 of 39


SANS SEC530: DEFENSIBLE SECURITY ARCHITECTURE AND
ENGINEERING EXAM 2026- QUESTIONS LATEST 2026 – 2027
VERSION SOLVED QUESTIONS & ANSWERS




SANS SEC530: Defensible Security Architecture and Engineering

250 Practice Exam Questions with Detailed Rationales



DOMAIN 1: DEFENSIBLE SECURITY ARCHITECTURE FUNDAMENTALS (Questions 1-
50)

1. Which of the following best defines "Defensible Security Architecture" as a core
concept that underpins the entire SEC530 framework for designing resilient
enterprise security systems?

A) A security model that focuses solely on strengthening the traditional network
perimeter to prevent all external attacks
B) A framework that assumes breaches will inevitably occur and therefore focuses on
building systems that can detect intrusions, respond effectively, and minimize damage
C) An architecture that relies entirely on signature-based detection mechanisms to
identify known threats before they can cause harm
D) A model that eliminates all system vulnerabilities through rigorous pre-deployment
testing and validation processes
E) A system that focuses exclusively on endpoint protection and ignores network-level
security controls

Correct Answer: B - Defensible Security Architecture acknowledges that no system is
perfectly secure and that breaches are inevitable. It emphasizes building systems that
can detect intrusions, respond effectively, and minimize damage—rather than
assuming a perfect perimeter can prevent all attacks . This philosophy shifts the focus
from prevention alone to a balanced approach incorporating detection and response
capabilities.

, Page 2 of 39




2. The DARIOM lifecycle in defensible security architecture encompasses which of
the following phases that guide the continuous improvement of security controls
and system resilience?

A) Discover, Assess, Remediate, Implement, Operate, Monitor
B) Design, Assess, Respond, Improve, Operate, Manage
C) Define, Architect, Review, Implement, Operate, Maintain
D) Discover, Assess, Remediate, Improve, Operate, Measure
E) Define, Analyze, Respond, Improve, Optimize, Monitor

Correct Answer: A - The DARIOM lifecycle stands for Discover, Assess, Remediate,
Implement, Operate, and Monitor. This framework guides security architects through a
continuous cycle of identifying assets and threats, assessing vulnerabilities,
implementing controls, and maintaining ongoing monitoring .



3. According to the Time-Based Security model, which of the following
mathematical relationships must hold true for an organization to achieve effective
security against a determined adversary?

A) Protection Time (P) must be less than Detection Time (D) plus Response Time (R)
B) Protection Time (P) must be greater than Detection Time (D) plus Response Time (R)
C) Protection Time (P) must equal Detection Time (D) plus Response Time (R)
D) Detection Time (D) must be greater than Protection Time (P) plus Response Time (R)
E) Response Time (R) must be greater than Protection Time (P) plus Detection Time (D)

Correct Answer: B - The Time-Based Security model states that for effective security,
the time a system can be protected (P) must be greater than the sum of detection time
(D) and response time (R). Mathematically, P > D + R. This means the organization must
be able to detect and respond to threats before the protection mechanisms fail .



4. The term "breakout point" in the context of a cyber attack timeline refers to
which critical moment that security architects must focus on detecting and
preventing?

A) The moment when an attacker first gains initial access to the network through a
phishing email or vulnerable service
B) The point in the attack when lateral movement first occurs, signaling that the attacker
is moving from the initial compromised host to other systems
C) The point when an attacker successfully exfiltrates sensitive data from the
organization's network

, Page 3 of 39


D) The moment when an attacker deploys ransomware and begins encrypting critical
files
E) The point when the attacker's command-and-control communication is first
established

Correct Answer: B - The breakout point is when lateral movement first occurs, signaling
the time when the attack moves beyond the initial compromised system to other
computers. This is when the attack becomes exponentially more dangerous and is a
critical point for detection and containment .



5. Which of the following countermeasures, as defined by the Cyber Kill Chain
framework, is intended to disrupt an attacker's ability to weaponize their exploits
and deliver malicious payloads to target systems?

A) Detect (identifying reconnaissance activities)
B) Deny (preventing the delivery of exploits)
C) Disrupt (interrupting command and control communications)
D) Degrade (reducing the effectiveness of the attack)
E) Deceive (misleading the attacker about the environment)

Correct Answer: B - The Cyber Kill Chain countermeasures include Detect, Deny,
Disrupt, Degrade, and Deceive. Deny is the countermeasure focused on preventing the
delivery of weaponized exploits to target systems, making it more difficult for attackers
to successfully execute their attack .



6. The OODA Loop, originally developed for military strategy, is applied in
cybersecurity to emphasize which of the following principles for maintaining an
effective defensive posture against evolving threats?

A) The organization should focus on having the most advanced prevention controls to
eliminate all threats
B) The organization must cycle through Observe, Orient, Decide, and Act faster than the
adversary can adapt
C) The organization should prioritize compliance with regulatory frameworks over
operational agility
D) The organization should rely on static security controls that require minimal
maintenance
E) The organization should focus exclusively on detection capabilities and ignore
prevention

Correct Answer: B - The OODA Loop (Observe, Orient, Decide, Act) is a decision-
making framework that emphasizes the importance of cycling through observation,

, Page 4 of 39


orientation, decision-making, and action faster than an adversary can adapt. This
allows defenders to make decisions at the speed of the adversary and maintain an
advantage .



7. What is the primary purpose of threat modeling using frameworks such as MITRE
ATT&CK in the context of defensible security architecture?

A) To create a comprehensive inventory of all potential vulnerabilities in the
organization's systems
B) To document all past security incidents for regulatory reporting and compliance
requirements
C) To understand adversary behaviors, identify defensive gaps, and prioritize security
controls based on real-world threats
D) To replace the need for penetration testing and vulnerability scanning programs
E) To assign blame and accountability for security failures to specific individuals or
departments

Correct Answer: C - Threat modeling with MITRE ATT&CK helps security architects
understand adversary behaviors, identify defensive gaps, and prioritize controls based
on real-world threats. It provides a common language for discussing threats and
enables more effective defensive design .



8. The principle of "defense-in-depth" differs from "defensible security
architecture" in which of the following fundamental ways that a security architect
must understand for effective system design?

A) Defense-in-depth focuses exclusively on network perimeter controls, while
defensible architecture focuses on endpoint protection
B) Defense-in-depth is a strategy of layering multiple security controls, while defensible
architecture emphasizes that breaches will occur and focuses on detection and
response
C) Defense-in-depth is obsolete and has been replaced entirely by Zero Trust models
D) Defense-in-depth is only applicable to physical security, not cybersecurity
E) Defense-in-depth and defensible architecture are identical concepts with no
meaningful distinction

Correct Answer: B - Defense-in-depth is the strategy of layering multiple, overlapping
security controls to provide redundancy. Defensible security architecture builds on this
by acknowledging that even layered defenses will eventually be breached, so the
architecture must be designed for effective detection, response, and recovery .

Document information

Uploaded on
August 24, 2026
Number of pages
39
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEJON
4.0
(2)
Sold
17
Followers
1
Items
4236
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions