Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 96 páginas
Examen

SANS SEC530 Exam 2026 Questions With Verified Answers

Document preview thumbnail
Vista previa 4 fuera de 96 páginas

SANS SEC530 Exam 2026 Questions With Verified Answers

Vista previa del contenido

SANS SEC530 Exam 2026 Questions With Verified Answers
Defensible Security Architecture & Engineering | GIAC GDSA Preparation

200 Practice Questions | Multiple Choice with Answer Key & Explanations



Question 1

Zero Trust fundamentally assumes:

A) Internal networks are safe and trusted

B) Every access request must be verified regardless of location

C) VPNs are unnecessary for security

D) Firewalls protect everything by default



Answer: B



Explanation: Zero Trust requires verification for every user, device, and access request regardless of
network location. It operates on the principle of "never trust, always verify," eliminating implicit trust even
for internal traffic



Question 2

What is the primary goal of a defensible security architecture?

A) Compliance with industry regulations

B) Reducing the attack surface

C) Maximizing return on security investments

D) Ensuring user productivity



Answer: B



Explanation: Reducing the attack surface is central to defensible architecture, limiting opportunities for
attackers to exploit systems. While compliance and ROI are considerations, attack surface reduction is the
primary architectural goal .

,Question 3

Micro-segmentation primarily helps to:

A) Reduce network latency

B) Prevent lateral movement of attackers

C) Encrypt all traffic end-to-end

D) Simplify VLAN design



Answer: B



Explanation: Micro-segmentation isolates workloads and creates security boundaries that restrict an
attacker's ability to move laterally across the network if a system is compromised .



Question 4

Which architecture concept ensures that no single component failure results in total system failure?

A) Least privilege

B) Redundancy

C) Encryption

D) Segmentation



Answer: B



Explanation: Redundancy provides alternate paths, systems, or components in case of failure, increasing
system reliability and availability. This is a fundamental principle of resilient security architecture .



Question 5

In Zero Trust, conditional access evaluates:

A) Only passwords and credentials

B) Device state, user identity, and contextual factors

C) Network latency and bandwidth

,D) VLAN assignment and subnet



Answer: B



Explanation: Conditional access in Zero Trust evaluates multiple factors including device posture, user
identity, location, time of access, and behavioral analytics before granting access to resources .



Question 6

What is the purpose of network segmentation?

A) Improve user authentication speed

B) Limit lateral movement and contain breaches

C) Encrypt all data in transit

D) Accelerate network traffic routing



Answer: B



Explanation: Network segmentation creates security boundaries that restrict an attacker's ability to move
laterally across the network. If one segment is compromised, segmentation prevents or slows spread to
other segments .



Question 7

Which of the following best defines Zero Trust Architecture?

A) Trust all internal traffic by default

B) Avoid encrypting internal data for performance

C) Always verify, never trust

D) Deploy firewalls at every endpoint

, Answer: C



Explanation: Zero Trust means continuous verification of every access request regardless of network
location, assuming no implicit trust is granted based solely on network position .



Question 8

Which project documents common tactics, techniques, and procedures (TTPs) that advanced persistent
threat groups use against enterprise networks?

A) DEF3NSE

B) DET3CT

C) ATP&CK

D) MITRE ATT&CK



Answer: D



Explanation: The MITRE ATT&CK framework is a globally accessible knowledge base of adversary tactics
and techniques based on real-world observations. It is used for threat modeling and defense strategy
development .



Question 9

Which of the following is described by Lockheed Martin as a countermeasure action to the Cyber Kill
Chain?

A) Disrupt

B) Prevent

C) React

D) Remove



Answer: A



Explanation: The Lockheed Martin Cyber Kill Chain framework identifies "Disrupt" as a countermeasure
action. Disrupt aims to break the attacker's chain at various phases to prevent successful compromise .

Información del documento

Subido en
10 de abril de 2026
Número de páginas
96
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$8.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
francisndungu1
5.0
(1)
Vendido
7
Seguidores
0
Artículos
589
Última venta
3 días hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes