Courseiva

GSEC · domain

Defensible Network Architecture

This GSEC domain covers building layered, monitored networks: segmentation, DMZs, NIDS/NIPS placement, switch port security, and DDoS-resistant perimeter design. Questions present engineer scenarios and configuration snippets, asking you to choose sensor placement, interpret switch behavior, and select architectural components that preserve visibility and resilience.

18 questions2 easy7 medium9 hard

Focused practice

Practice Defensible Network Architecture questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Defensible Network Architecture

You must be able to choose correct sensor placement (tap, SPAN, inline) for full visibility, interpret port security violation actions, and assemble layered perimeter defenses. The single most important thing: ensure monitoring sees all relevant traffic, including east-west, without drops.

Placing NIDS sensors at choke points such as SPAN ports, taps, or inline to see all packets

Configuring switch port security (sticky MAC, violation modes) to block unauthorized devices

Deploying sensors to capture east-west traffic between VMs in virtualized clusters

Selecting perimeter components like load balancers, WAFs, and DDoS scrubbing for resilience

Watch out for

Common Defensible Network Architecture exam traps

  • ▸Assuming a SPAN port sees all traffic; oversubscription or misconfigured VLANs can drop packets, hiding attacks from the NIDS.
  • ▸Forgetting that port security violation modes (protect, restrict, shutdown) differ in logging and whether the port actually goes down.
  • ▸Placing NIDS only at the perimeter, missing east-west traffic inside virtualization clusters where lateral movement occurs.

Question index

All Defensible Network Architecture questions (18)

Click any question to see the full explanation, or start a practice session above.

1

During an internal network security audit, an engineer discovers that workstations on the human resources VLAN can directly communicate with sensitive database servers on the finance VLAN without passing through a filtering device. Which foundational architectural control is missing from this environment?

Medium
2

A financial services firm is deploying a new high-security network segment for trading systems. The security team wants to prevent unauthorized devices from communicating on the segment even if they physically connect to an access switch port. The chosen solution must authenticate the device before any network access is granted and must integrate with the existing RADIUS server. Which technology should be implemented?

Hard
3

A security engineer is segmenting a data center so that contractors who maintain HVAC systems cannot initiate connections into the server VLAN, but the internal monitoring platform must still reach the contractor subnet to poll building-management sensors. The chosen design uses a stateful firewall between the two zones with the contractor zone as the untrusted side. Which configuration best enforces the required traffic direction while preserving monitoring?

Medium
4

A security administrator is configuring a screened subnet (DMZ) firewall rule set. The organization wants to allow external users to reach a public web server on TCP 443 while preventing the web server from initiating connections back into the internal network. Which rule set BEST enforces this requirement?

Easy
5

A security architect is designing a defensible network architecture for a new campus. The architect must implement controls that limit the spread of malware from an infected endpoint to other endpoints on the same VLAN. Which TWO actions should be included in the design? (Choose two.)

Hard
6

An organization is hardening its internal corporate network architecture to prevent unauthorized hosts from connecting to switch ports in common areas and conference rooms. Which TWO configurations should the network engineering team implement to achieve this security objective? (Choose TWO)

Hard
7

An enterprise network design utilizes an out-of-band management network for all core routers, firewalls, and switches. The management network is physically separated from the production data plane and uses dedicated management switches. What is the primary security advantage of this defensible architecture?

Hard
8

A security architect is hardening an organization's network infrastructure against reconnaissance and layer-2 attacks. Which TWO actions should the engineering team take to mitigate common switch-based vulnerabilities? (Choose TWO)

Medium
9

Refer to the exhibit. A network administrator configured port security on a switch interface to protect against unauthorized device connections. Based on the provided configuration snippet, what action will the switch take if a third device with an unknown MAC address connects to this port?

Medium
10

A financial firm is architecting a new cardholder data environment (CDE) that must comply with PCI DSS segmentation requirements. The security team proposes using a single internal VLAN with host-based firewalls on each server to isolate CDE systems from corporate desktops. The auditor rejects this design. Which approach BEST meets the requirement for defensible network segmentation?

Medium
11

An architect is designing a defensible architecture that must detect reconnaissance scanning against a sensitive research subnet without alerting on normal vulnerability-scanner traffic that the security team runs weekly from an authorized scanner host. The design will use an intrusion detection sensor on a SPAN port. Which combination of capabilities best meets the requirement?

Hard
12

A junior administrator is asked to make a web server reachable from the internet without exposing the internal database server that the web application uses. The web server sits in a screened subnet, and the database resides on the internal network. Which architecture correctly implements this requirement?

Easy
13

A security team is designing a resilient perimeter architecture to protect internal services from distributed denial of service attacks and web application exploits. Which THREE architectural components must be incorporated into this design? (Choose THREE)

Hard
14

A security engineer is deploying a network-based intrusion detection system (NIDS) to monitor traffic entering and leaving a data center. The engineer needs to ensure the sensor can see all packets, including those that are fragmented or have errors, without affecting the production traffic flow. Which deployment method should be used?

Medium
15

A security engineer is designing a secure enterprise environment and needs to deploy network intrusion detection sensors to monitor east-west traffic moving between virtual machines inside an internal virtualization cluster. Which deployment method ensures the sensors successfully inspect internal segment traffic without introducing a single point of failure for packet forwarding?

Hard
16

A security architect must ensure that hosts on a guest wireless network cannot reach any internal RFC 1918 subnets, while still allowing guests to reach the internet and a captive portal hosted internally for authentication. The design uses a wireless controller that tunnels guest traffic to a dedicated guest anchor. Which approach best enforces the requirement?

Hard
17

A network architect is designing a new data center fabric that must support a large number of tenants with strict isolation requirements. The design uses a spine-leaf topology with VXLAN overlay. The architect must ensure that broadcast, unknown unicast, and multicast (BUM) traffic from one tenant never reaches another tenant's virtual tunnel endpoints (VTEPs). Which mechanism should be implemented to meet this requirement?

Hard
18

An enterprise network administrator needs to isolate a new public-facing web application so that a compromise of the web server does not immediately expose the internal corporate database and directory services. Which network architecture design pattern provides the most effective defense for this scenario?

Medium

Frequently asked questions

What does the Defensible Network Architecture domain cover on the GSEC exam?
You must be able to choose correct sensor placement (tap, SPAN, inline) for full visibility, interpret port security violation actions, and assemble layered perimeter defenses. The single most important thing: ensure monitoring sees all relevant traffic, including east-west, without drops.
How many questions are in this domain?
This page lists all 18 Defensible Network Architecture questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Defensible Network Architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC defensible network architecture Practice Questions