GIAC Defensible Security Architect Certification assessment
Proctored objective assessment using multiple-choice, multiple-response, or scenario-based items as specified by the provider.
- Type
- Written
- Delivery
- Both
Exam sections
Cloud-based Security Architecture
Within the wider assessment, Cloud-based Security Architecture tests whether a candidate can connect core principles with defensible execution and verification. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
In the context of GIAC Defensible Security Architect Certification, the Cloud-based Security Architecture objectives indicate that the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Turn every major objective in Cloud-based Security Architecture into a decision question. Explain the preferred option, the risk in the strongest alternative, and the observation or artifact that would verify success. That exercise should make the role of Cloud-based Security Architecture within GIAC Defensible Security Architect Certification concrete.
Data Discovery, Governance, and Mobility Management
Here the emphasis is on applying data discovery, governance, and mobility management to realistic technical, operational, governance, legal, or business situations. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
A candidate working through Data Discovery, Governance, and Mobility Management should remember that assessment items can test recognition of a sound approach, diagnosis of an incorrect one, or completion of a practical step. Treat official weighting separately from any unofficial study emphasis.
Preparation tips
Create a one-page model of how Data Discovery, Governance, and Mobility Management connects to the preceding and following domains. Use scenario questions to rehearse boundary decisions and identify when another specialist or control is needed. A final self-check should explain why Data Discovery, Governance, and Mobility Management matters to the candidate profile for this credential.
Data-Centric Security
Data-Centric Security covers the decisions practitioners make before, during, and after implementing or evaluating this capability. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
The blueprint's treatment of Data-Centric Security indicates that expect Data-Centric Security to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Practice data-centric security in the environment or professional context the credential targets. After each exercise, explain the dependencies, likely failure signals, and safe recovery or escalation path. A final self-check should explain why Data-Centric Security matters to the candidate profile for this credential.
Fundamental Layer 3 Defense
Questions or tasks in Fundamental Layer 3 Defense explore more than terminology: candidates need to recognize appropriate methods, dependencies, and failure conditions. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
For Fundamental Layer 3 Defense, the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Study from outcomes backward: define what a successful fundamental layer 3 defense result looks like, list the steps or controls that produce it, and practice spotting evidence that the process has drifted. Revisit the exercise if the explanation cannot distinguish Fundamental Layer 3 Defense from a neighboring blueprint area.
Fundamental Security Architecture Concepts
This section treats fundamental security architecture concepts as an applied responsibility, including the surrounding inputs, controls, trade-offs, and evidence of success. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
A candidate working through Fundamental Security Architecture Concepts should remember that the provider's outline defines the subject boundary, but individual items may combine it with neighboring domains. Read for constraints and desired outcomes before selecting or performing an action.
Preparation tips
Explain this domain aloud as if handing work to a colleague. Include prerequisites, common mistakes, security or governance implications, and how you would test that the result meets its objective. That exercise should make the role of Fundamental Security Architecture Concepts within GIAC Defensible Security Architect Certification concrete.
IPv6
Within the wider assessment, IPv6 tests whether a candidate can connect core principles with defensible execution and verification. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
The blueprint's treatment of IPv6 indicates that the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Study from outcomes backward: define what a successful ipv6 result looks like, list the steps or controls that produce it, and practice spotting evidence that the process has drifted. Keep the resulting notes under the IPv6 heading so gaps remain visible during mixed review.
Layer 1/Layer 2 Defense
This section treats layer 1/layer 2 defense as an applied responsibility, including the surrounding inputs, controls, trade-offs, and evidence of success. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
The blueprint's treatment of Layer 1/Layer 2 Defense indicates that assessment items can test recognition of a sound approach, diagnosis of an incorrect one, or completion of a practical step. Treat official weighting separately from any unofficial study emphasis.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because Layer 1/Layer 2 Defense is likely to interact with other responsibilities rather than remain an isolated fact set. A final self-check should explain why Layer 1/Layer 2 Defense matters to the candidate profile for this credential.
Network Defenses
The Network Defenses domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
At the Network Defenses stage of the outline, the provider's outline defines the subject boundary, but individual items may combine it with neighboring domains. Read for constraints and desired outcomes before selecting or performing an action.
Preparation tips
Build a small practice set for network defenses: one normal workflow, one deliberately broken case, and one comparison between competing approaches. Record what evidence confirms the correct outcome. Keep the resulting notes under the Network Defenses heading so gaps remain visible during mixed review.
Network Encryption and Remote Access
Network Encryption and Remote Access covers the decisions practitioners make before, during, and after implementing or evaluating this capability. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
At the Network Encryption and Remote Access stage of the outline, the provider's outline defines the subject boundary, but individual items may combine it with neighboring domains. Read for constraints and desired outcomes before selecting or performing an action.
Preparation tips
Study from outcomes backward: define what a successful network encryption and remote access result looks like, list the steps or controls that produce it, and practice spotting evidence that the process has drifted. That exercise should make the role of Network Encryption and Remote Access within GIAC Defensible Security Architect Certification concrete.
Network Proxies and Firewalls
The scope of Network Proxies and Firewalls includes both understanding the subject and choosing an effective response when conditions or objectives change. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
The blueprint's treatment of Network Proxies and Firewalls indicates that the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Turn every major objective in Network Proxies and Firewalls into a decision question. Explain the preferred option, the risk in the strongest alternative, and the observation or artifact that would verify success. Revisit the exercise if the explanation cannot distinguish Network Proxies and Firewalls from a neighboring blueprint area.
Zero Trust Endpoints
This section treats zero trust endpoints as an applied responsibility, including the surrounding inputs, controls, trade-offs, and evidence of success. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
When GIAC Defensible Security Architect Certification reaches Zero Trust Endpoints, this domain may be assessed independently or as part of a scenario crossing other blueprint areas. Pay attention to the wording that changes scope, responsibility, risk, or the best next action.
Preparation tips
Turn every major objective in Zero Trust Endpoints into a decision question. Explain the preferred option, the risk in the strongest alternative, and the observation or artifact that would verify success. Keep the resulting notes under the Zero Trust Endpoints heading so gaps remain visible during mixed review.
Zero Trust Fundamentals
Here the emphasis is on applying zero trust fundamentals to realistic technical, operational, governance, legal, or business situations. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
A candidate working through Zero Trust Fundamentals should remember that the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because Zero Trust Fundamentals is likely to interact with other responsibilities rather than remain an isolated fact set. Keep the resulting notes under the Zero Trust Fundamentals heading so gaps remain visible during mixed review.
