Domain 1: Defensible Network Architecture
GIAC Certified Enterprise Defender · 50 questions
- Your organization is redesigning its network architecture after a breach that allowed lateral movement from the guest Wi-Fi network to internal servers. Which design principle most directly addresses this failure?
- A security architect is designing a DMZ for a web application that must communicate with a backend database. Which firewall rule set best represents defensible architecture?
- During a network architecture review, you find that all VLANs can communicate with each other through a core switch with no inter-VLAN ACLs. The organization has PCI-scoped systems in VLAN 10 and user workstations in VLAN 20. What is the MOST critical remediation?
- An organization wants to allow remote employees to access internal resources. The security team must choose between a split-tunnel VPN and a full-tunnel VPN. Which statement BEST describes the security trade-off?
- A hospital network has medical devices running legacy operating systems that cannot be patched. Which network architecture control BEST reduces the risk these devices pose?
- An organization uses 802.1X for network access control. An attacker attempts to connect an unauthorized laptop to a wired port. Which 802.1X behavior BEST prevents unauthorized access?
- A security engineer is configuring egress filtering on the corporate firewall. Which approach BEST represents a defensible egress policy?
- During an architecture review, you discover the organization has no out-of-band management network for network devices. Why is an out-of-band management network considered a key element of defensible architecture?
- An organization wants to enforce network access controls based on the health posture of connecting endpoints. Which technology BEST enables this capability?
- A network architect is designing a new branch office. The branch hosts a public-facing web application, an internal HR portal, and manufacturing control systems (OT). Which segmentation model best reduces lateral movement risk if any one segment is compromised?
- A firewall admin reviews a ruleset and finds: Rule 1 ALLOW any → 10.0.0.50:443, Rule 2 DENY 192.168.10.0/24 → any, Rule 3 ALLOW 192.168.10.5 → 10.0.0.50:443. Which statement is accurate about Rule 3?
- Your organization must allow vendor remote access to an OT environment for maintenance windows. Which architecture best balances operational need with security?
- An analyst discovers that internal workstations can initiate connections to any external IP on port 80 and 443 without restriction. Which control would most improve the defensibility of this architecture?
- A defense-in-depth review reveals the perimeter firewall is the only control between the internet and a critical database server. Which additional architectural layer provides the most immediate risk reduction?
- During a network architecture review, a team finds that two business units share the same VLAN and IP subnet. A compromise of a workstation in Unit A led to credential harvesting across Unit B via SMB relay. Which architectural remedy directly addresses this threat?
- A company's cloud-hosted workloads in AWS communicate with on-premises systems via a VPN tunnel. Security requirements mandate that cloud workloads must not have direct paths to the on-premises OT segment. Which control enforces this?
- A new DMZ web server needs to communicate with an internal database server on port 1433 (MSSQL). The security team must allow this while maintaining least-privilege firewall rules. Which rule set is most appropriate?
- A network architect is designing a new enterprise segment and wants to enforce the principle of least privilege at the network layer. Which approach best achieves this goal?
- An organization wants to implement network access control (NAC) to ensure only compliant endpoints connect to the production VLAN. Which 802.1X component authenticates the endpoint device?
- A security engineer is designing a DMZ for a public-facing web application. Which firewall rule policy best follows defense-in-depth principles?
- Which concept describes the practice of positioning network taps and security sensors so that no traffic path exists that cannot be monitored?
- A company is designing a new data center network. The security team insists on using out-of-band management for all network devices. What is the primary security benefit?
- An organization deploys network-based encryption between all internal hosts using IPsec in tunnel mode. Which security monitoring challenge does this create?
- A CISO asks the network team to design a network that assumes breach. Which architecture element is most aligned with this philosophy?
- Which protocol should be disabled on network switches to prevent VLAN hopping attacks?
- A network architect is evaluating whether to use a stateful inspection firewall or a next-generation firewall (NGFW) for a new deployment. What capability does an NGFW provide that a traditional stateful firewall lacks?
- A network security architect is tasked with redesigning the enterprise network to reduce the attack surface. Which approach directly reduces the number of exploitable network paths an attacker can take?
- An organization uses an intrusion prevention system (IPS) inline between the internet router and the core firewall. What risk does this introduce if not managed correctly?
- A defensible network architecture principle states that adversaries must traverse known, controlled paths. Which control most directly enforces this for internal lateral movement?
- A security architect is evaluating whether to use a Software-Defined Networking (SDN) approach for network segmentation. What key advantage does SDN provide over traditional VLAN-based segmentation?
- A company wants to ensure that wireless guest networks cannot reach corporate internal resources. Which architectural control achieves this most effectively?
- A network engineer wants to capture full packet data (PCAP) from a high-speed 10Gbps link. Which deployment method is preferred to avoid dropping packets?
- What is the security purpose of deploying a honeypot inside an enterprise network (internal honeypot)?
- An organization wants to detect rogue wireless access points connected to the corporate wired network. Which technique is most effective at identifying unauthorized wireless devices?
- A network architect is implementing a zero-trust architecture. Which statement best describes the core principle of zero trust regarding network location?
- An organization wants to ensure that its egress filtering policy prevents data exfiltration. Which egress filtering strategy is most effective?
- A network security engineer is designing a network where a compromised host in the employee VLAN should not be able to directly communicate with servers in the production VLAN. Which Layer 3 control enforces this?
- A security team wants to collect full-content packet capture at multiple network choke points without impacting production traffic. The preferred method is passive monitoring. Which technology achieves this?
- An organization is designing its network security architecture and the CISO requires separation between the management plane of network devices and the data plane. What does this separation achieve?
- A security team is evaluating network access control solutions. What is the primary limitation of using only MAC address filtering for network access control?
- An organization's security policy requires that all network devices use encrypted management protocols. Which statement correctly distinguishes Telnet from SSH for device management?
- A network architect is documenting the organization's security architecture. What is a 'security zone' in the context of network architecture?
- A network architect must provide reliable internet access for business-critical applications while maintaining security controls. Which topology provides both resilience and inspection of all internet-bound traffic?
- An organization discovers that an attacker was able to exfiltrate data by establishing outbound connections to cloud storage services that were not blocked by the firewall. What specific control gap does this represent?
- A security architect is designing network zones for a new enterprise. Which principle governs how services should be placed across zones to minimize attack surface?
- Which technique does an attacker use to maintain a persistent foothold in a network by registering a domain that closely resembles a legitimate organization's domain (e.g., 'g00gle.com' vs 'google.com')?
- A security engineer is implementing network access control using 802.1X. When a non-compliant device connects, it should be placed in a restricted VLAN allowing only remediation traffic. What is this VLAN called?
- An attacker performs reconnaissance and discovers that the target organization uses a BGP autonomous system number and announces specific IP prefixes to the internet. How could a threat actor attempt to exploit this information?
- A network security architect wants to implement network policy enforcement ensuring that only authorized systems can communicate with production database servers. Which approach provides the strongest guarantee without relying solely on firewall rules?
- A cloud-first organization deploys workloads in AWS and wants to apply network security monitoring equivalent to on-premises NSM. Which AWS service provides VPC-level network traffic visibility for analysis?