SANS SEC530 Exam 2026 Questions With Verified Answers
Defensible Security Architecture & Engineering | GIAC GDSA Preparation
200 Practice Questions | Multiple Choice with Answer Key & Explanations
Question 1
Zero Trust fundamentally assumes:
A) Internal networks are safe and trusted
B) Every access request must be verified regardless of location
C) VPNs are unnecessary for security
D) Firewalls protect everything by default
Answer: B
Explanation: Zero Trust requires verification for every user, device, and access request regardless of
network location. It operates on the principle of "never trust, always verify," eliminating implicit trust even
for internal traffic
Question 2
What is the primary goal of a defensible security architecture?
A) Compliance with industry regulations
B) Reducing the attack surface
C) Maximizing return on security investments
D) Ensuring user productivity
Answer: B
Explanation: Reducing the attack surface is central to defensible architecture, limiting opportunities for
attackers to exploit systems. While compliance and ROI are considerations, attack surface reduction is the
primary architectural goal .
,Question 3
Micro-segmentation primarily helps to:
A) Reduce network latency
B) Prevent lateral movement of attackers
C) Encrypt all traffic end-to-end
D) Simplify VLAN design
Answer: B
Explanation: Micro-segmentation isolates workloads and creates security boundaries that restrict an
attacker's ability to move laterally across the network if a system is compromised .
Question 4
Which architecture concept ensures that no single component failure results in total system failure?
A) Least privilege
B) Redundancy
C) Encryption
D) Segmentation
Answer: B
Explanation: Redundancy provides alternate paths, systems, or components in case of failure, increasing
system reliability and availability. This is a fundamental principle of resilient security architecture .
Question 5
In Zero Trust, conditional access evaluates:
A) Only passwords and credentials
B) Device state, user identity, and contextual factors
C) Network latency and bandwidth
,D) VLAN assignment and subnet
Answer: B
Explanation: Conditional access in Zero Trust evaluates multiple factors including device posture, user
identity, location, time of access, and behavioral analytics before granting access to resources .
Question 6
What is the purpose of network segmentation?
A) Improve user authentication speed
B) Limit lateral movement and contain breaches
C) Encrypt all data in transit
D) Accelerate network traffic routing
Answer: B
Explanation: Network segmentation creates security boundaries that restrict an attacker's ability to move
laterally across the network. If one segment is compromised, segmentation prevents or slows spread to
other segments .
Question 7
Which of the following best defines Zero Trust Architecture?
A) Trust all internal traffic by default
B) Avoid encrypting internal data for performance
C) Always verify, never trust
D) Deploy firewalls at every endpoint
, Answer: C
Explanation: Zero Trust means continuous verification of every access request regardless of network
location, assuming no implicit trust is granted based solely on network position .
Question 8
Which project documents common tactics, techniques, and procedures (TTPs) that advanced persistent
threat groups use against enterprise networks?
A) DEF3NSE
B) DET3CT
C) ATP&CK
D) MITRE ATT&CK
Answer: D
Explanation: The MITRE ATT&CK framework is a globally accessible knowledge base of adversary tactics
and techniques based on real-world observations. It is used for threat modeling and defense strategy
development .
Question 9
Which of the following is described by Lockheed Martin as a countermeasure action to the Cyber Kill
Chain?
A) Disrupt
B) Prevent
C) React
D) Remove
Answer: A
Explanation: The Lockheed Martin Cyber Kill Chain framework identifies "Disrupt" as a countermeasure
action. Disrupt aims to break the attacker's chain at various phases to prevent successful compromise .
Defensible Security Architecture & Engineering | GIAC GDSA Preparation
200 Practice Questions | Multiple Choice with Answer Key & Explanations
Question 1
Zero Trust fundamentally assumes:
A) Internal networks are safe and trusted
B) Every access request must be verified regardless of location
C) VPNs are unnecessary for security
D) Firewalls protect everything by default
Answer: B
Explanation: Zero Trust requires verification for every user, device, and access request regardless of
network location. It operates on the principle of "never trust, always verify," eliminating implicit trust even
for internal traffic
Question 2
What is the primary goal of a defensible security architecture?
A) Compliance with industry regulations
B) Reducing the attack surface
C) Maximizing return on security investments
D) Ensuring user productivity
Answer: B
Explanation: Reducing the attack surface is central to defensible architecture, limiting opportunities for
attackers to exploit systems. While compliance and ROI are considerations, attack surface reduction is the
primary architectural goal .
,Question 3
Micro-segmentation primarily helps to:
A) Reduce network latency
B) Prevent lateral movement of attackers
C) Encrypt all traffic end-to-end
D) Simplify VLAN design
Answer: B
Explanation: Micro-segmentation isolates workloads and creates security boundaries that restrict an
attacker's ability to move laterally across the network if a system is compromised .
Question 4
Which architecture concept ensures that no single component failure results in total system failure?
A) Least privilege
B) Redundancy
C) Encryption
D) Segmentation
Answer: B
Explanation: Redundancy provides alternate paths, systems, or components in case of failure, increasing
system reliability and availability. This is a fundamental principle of resilient security architecture .
Question 5
In Zero Trust, conditional access evaluates:
A) Only passwords and credentials
B) Device state, user identity, and contextual factors
C) Network latency and bandwidth
,D) VLAN assignment and subnet
Answer: B
Explanation: Conditional access in Zero Trust evaluates multiple factors including device posture, user
identity, location, time of access, and behavioral analytics before granting access to resources .
Question 6
What is the purpose of network segmentation?
A) Improve user authentication speed
B) Limit lateral movement and contain breaches
C) Encrypt all data in transit
D) Accelerate network traffic routing
Answer: B
Explanation: Network segmentation creates security boundaries that restrict an attacker's ability to move
laterally across the network. If one segment is compromised, segmentation prevents or slows spread to
other segments .
Question 7
Which of the following best defines Zero Trust Architecture?
A) Trust all internal traffic by default
B) Avoid encrypting internal data for performance
C) Always verify, never trust
D) Deploy firewalls at every endpoint
, Answer: C
Explanation: Zero Trust means continuous verification of every access request regardless of network
location, assuming no implicit trust is granted based solely on network position .
Question 8
Which project documents common tactics, techniques, and procedures (TTPs) that advanced persistent
threat groups use against enterprise networks?
A) DEF3NSE
B) DET3CT
C) ATP&CK
D) MITRE ATT&CK
Answer: D
Explanation: The MITRE ATT&CK framework is a globally accessible knowledge base of adversary tactics
and techniques based on real-world observations. It is used for threat modeling and defense strategy
development .
Question 9
Which of the following is described by Lockheed Martin as a countermeasure action to the Cyber Kill
Chain?
A) Disrupt
B) Prevent
C) React
D) Remove
Answer: A
Explanation: The Lockheed Martin Cyber Kill Chain framework identifies "Disrupt" as a countermeasure
action. Disrupt aims to break the attacker's chain at various phases to prevent successful compromise .