Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Document preview thumbnail
Aperçu 4 sur 77 pages
Examen

SANS SEC530: Defensible Security Architecture and Engineering Questions and Answers 2026/2027 | SANS Institute | A+ Certification Practice Questions with Verified Answers

Document preview thumbnail
Aperçu 4 sur 77 pages

contains comprehensive practice questions and answers for SANS SEC530: Defensible Security Architecture and Engineering. It covers core topics such as enterprise security architecture, Zero Trust principles, identity and access management (IAM), network segmentation, cloud and hybrid infrastructure security, threat modeling, risk management, resilience, secure design principles, security governance, and architecture frameworks to help learners prepare for SEC530 coursework and related GIAC certification objectives. The material is suitable for cybersecurity architects, security engineers, consultants, and IT professionals looking to reinforce key security architecture concepts through exam-style practice.

Aperçu du contenu

SANS - SEC530 questions and answers 2026\2027 A+ Grade


Which of the following is a recommended USB keyboard mitigation for sites requiring high security?



A) Disable USB ports in the system.

B) Restrict USB devices with approved PIDs and VIDs.

C) Block the USB devices physically.

D) Restrict USB devices with approved user accounts.
- correct answer C) Block the USB devices physically.



Which of the following Cisco IOS commands is used to shut the port down automatically when the
maximum number of MAC addresses is exceeded?



A) switchport port-security violation shutdown

B) switchport port-security limit rate source-mac-shutdown

C) switchport port-security violation auto-shutdown

D) switchport port-security mac-exceed-port-shutdown
- correct answer A) switchport port-security violation shutdown



What is a common failing associated with focusing only on compliance-drive security?



A) Compliance-driven security tends to focus only on hardening internal systems.

B) Compliance-driven security tends to focus only on hardening the perimeter.

C) Compliance-driven security tends to be costly in terms of solutions and resources.

D) Compliance-driven security tends to fail in the face of a persistent adversary.
- correct answer D) Compliance-driven security tends to fail in the face of a persistent adversary.



Which of the following is described by Lockheed Martin as a countermeasure action to the Kill Chain?

,A) Disrupt

B) Prevent

C) React

D) Remove
- correct answer A) Disrupt



What is an easy to implement and effective control an organization can leverage to make pivoting more
difficult for an attacker?



A) WPA2

B) P2P patching

C) Private VLAN

D) VPN
- correct answer C) Private VLAN



Which type of private VLAN ports may only communicate with promiscuous ports?



A) Isolated

B) Promiscuous

C) Network

D) Community
- correct answer A) Isolated



Which of the following wireless standards supports up to 1300 Mbps?



A) 802.11b

B) 802.11ac

C) 802.11n

,D) 802.11w
- correct answer B) 802.11ac



In which phase of the security architecture design lifecycle is threat modeling and attack surface analysis
conducted?



A) Scan

B) Discover and Assess

C) Plan

D) Design
- correct answer C) Plan



Which of the following is the best practice to mitigate against the Cisco Discovery Protocol (CDP)
information leakage attack?



A) Disable the CDP unless expressly required.

B) No mitigations are needed since CDP is secure by default.

C) Schedule the CDP patch regularly.

D) Enable the SECDP feature in the CDP to secure the CDP.
- correct answer A) Disable the CDP unless expressly required.



Which of the following prevents physical access to the network when plugging in an unauthorized
device?



A) MAC address filtering

B) Packet filtering firewall

C) Background checks

D) Two-factor authentication
- correct answer A) MAC address filtering



What would be one of the first steps for a security architect when building or redesigning a security
architecture to secure an organization?

, A) Remove unnecessary egress traffic

B) Perform a perimeter pen test

C) Deploy patches to external systems

D) Identify critical assets
- correct answer D) Identify critical assets



Which of the following is a method of detecting a BYOAP problem on a network?



A) Multiple VPN connections from the internal network.

B) Multiple URL requests from the same source IP.

C) Multiple SSIDs in the area.

D) Multiple user agent strings from the same IP address.
- correct answer D) Multiple user agent strings from the same IP address.



What could be implemented to mitigate the risk of one client pivoting to another on the same network?



A) Host-based antipivot

B) Next-gen antivirus

C) NAC controls

D) Private VLANs
- correct answer D) Private VLANs



What is the term used for when the red team is working together with the blue team through simulation
of specific threat scenarios?



A) Purple teaming

B) Black-hat teaming

C) Defensive teaming

Infos sur le Document

Publié le
27 juin 2026
Nombre de pages
77
Écrit en
2025/2026
Type
Examen
Contenu
Questions et réponses
27,36 €

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
LECPOPC
3,8
(12)
Vendu
70
Abonnés
4
Éléments
6133
Dernière vente
5 jours de cela



Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Vous travaillez sur vos références ?

Créez des citations précises en APA, MLA et Harvard avec notre générateur de sources gratuit.

Vous travaillez sur vos références ?

Foire aux questions