GIAC GDSA defensible security architecture banner showing layered network defenses from switching to cloud

Defensible Security Architecture: What GDSA Tests From Layer 1 to the Cloud

Defensible security architecture is the practice of designing a network so that it keeps working against an attacker who is already inside it, rather than one that only holds while the perimeter holds. GIAC certifies it as GDSA, the Defensible Security Architect credential, and the exam is 75 questions in two hours with a pass mark of 63 percent.

What makes GDSA unusual is its span. The thirteen exam objectives start at Layer 1 with VLANs and MAC spoofing and finish at container security and mobile device management, taking in IPv6, proxies, data loss prevention and four separate Zero Trust topics along the way. GIAC publishes no percentage weightings for any of it, which changes how you have to prepare. This article groups those thirteen objectives into something you can plan around.

What Does Defensible Security Architecture Actually Mean?

A defensible architecture assumes compromise rather than preventing it. The GDSA objectives name this directly: perimeter-focused deficiencies, presumption of compromise, the Zero Trust model, the Intrusion Kill Chain, the Diamond Model, micro-segmentation, threat vector analysis and attack surface analysis all sit in a single foundational objective. The design goal is a network where an intruder’s next move is slow, noisy and constrained.

That is a different discipline from securing a perimeter. A perimeter design asks what gets in. A defensible design asks what an attacker can reach once they are in, how quickly you would notice, and how much of the estate one compromised credential actually unlocks. The exam is built around that shift, which is why it reaches from cabling standards to cloud containers.

“Holders of the GIAC Defensible Security Architect (GDSA) certification have proved to be all-round defenders, capable of designing, implementing and tuning an effective combination of network-centric and data-centric controls to balance prevention, detection, and response.”

Ismael Valenzuela, Author of SANS SEC530

The two halves of the credential

The quote above names the split that organises the whole syllabus: network-centric controls and data-centric controls. Roughly two thirds of the objectives concern the network, from Layer 1 defence up through proxies and firewalls to encrypted remote access. The remaining third concerns the data itself, through classification, loss prevention, database governance and monitoring. A candidate strong in one half and absent in the other will struggle, because the exam treats them as one design problem.

What Does the GDSA Exam Cost, and How Is It Scored?

GDSA costs $999 for a certification attempt and consists of 75 questions in two hours, with a minimum passing score of 63 percent. It is a single proctored exam, delivered either through remote proctoring or at a test centre. Once an attempt is activated in your GIAC account, you have 120 days to complete it.

ItemDetail
Exam codeGDSA
Questions75
Duration2 hours
Passing score63 percent
Price$999 USD per attempt
ProctoringRemote through ProctorU, or onsite at a Pearson VUE centre
Window to sit120 days from activation
Associated courseSANS SEC530

The 63 percent figure looks arbitrary and is not. GIAC sets its pass marks through a psychometric standard-setting study rather than by picking a round number, and this one applies to every exam version released from 3 August 2019 onward. Comparing the objectives against the GDSA exam page is a quick way to judge how much of the ground you already hold.

Two hours for 75 questions is not generous

That is 96 seconds per question across thirteen subject areas, several of which require you to reason about a design rather than recall a definition. GIAC exams are open book, which helps, but only if your reference material is indexed well enough to find something inside a minute. An unindexed pile of course books costs more time than it saves.

Remote or onsite

All GIAC exams are web-based and proctored, and there are two routes: remote proctoring through ProctorU, or onsite proctoring at a Pearson VUE test centre. Some published summaries list only the test centre option, so it is worth knowing the remote route exists before planning travel around an exam date.

Why Does GDSA Start at Layer 1 and Not at the Firewall?

Three of the thirteen objectives sit below the firewall: Layer 1 and Layer 2 defence, fundamental Layer 3 defence, and IPv6. GDSA starts there because the attacks that undo a good perimeter design mostly happen underneath it. ARP cache poisoning, VLAN hopping and DHCP starvation do not care how well the edge is configured.

Four Layer 2 attacks tested by GDSA: ARP poisoning, VLAN hopping, DHCP starvation and MAC spoofing

What Layer 1 and Layer 2 covers

VLAN structure and deployment, CDP, MAC spoofing, ARP cache poisoning, DHCP starvation, VLAN hopping, 802.1X and network access control. This is switching security rather than firewall policy, and it is the objective most often underestimated by candidates whose day job is higher up the stack.

What Layer 3 covers

CIDR, routing attacks and their mitigations, Layer 2 and Layer 3 benchmarking and auditing tools, securing SNMP and NTP, and bogon filtering. SNMP and NTP are worth singling out: both are ordinary infrastructure services that quietly become reconnaissance and manipulation channels when left at their defaults.

Why IPv6 gets its own objective

IPv6 is one of thirteen objectives on its own, covering addressing, dual stack systems, tunnelling, and router advertisement attacks and their mitigation. The reason is dual stack. A network that has not deliberately adopted IPv6 usually still has it enabled, which means a second address family that nobody is monitoring and no policy covers. The details of the IPv6 specification matter here because router advertisement attacks exploit the protocol working exactly as designed.

How Much of GDSA Is Zero Trust?

Four of the thirteen objectives are explicitly Zero Trust: Zero Trust Fundamentals, Zero Trust Networking, Zero Trust Endpoints, and the Zero Trust model inside the foundational architecture objective. That is close to a third of the named subject matter, and the associated SANS course carries Zero Trust in its title. It is the organising idea of the credential rather than one topic among many.

The three Zero Trust objectives, and what separates them

  • Fundamentals covers Zero Trust architecture as a concept, credential rotation, and responding to pivoting adversaries and insider threats.
  • Networking covers authenticating and encrypting endpoint traffic, domain isolation, single packet authentication, red herring defences, and proactive measures designed to change attacker behaviour.
  • Endpoints covers patching via automation, end-user privilege reduction, host hardening, host IDS and IPS, endpoint firewalls, and scaling endpoint log collection.

Single packet authentication and red herring defences are the entries that catch people out, because neither appears in most Zero Trust marketing material. They belong to the older tradition of making a service invisible or misleading rather than merely gated, and the exam expects you to know what they do.

Because Zero Trust is a maturity journey rather than a product, it helps to see it described as stages by an independent body. The Zero Trust Maturity Model breaks the same ideas into pillars and progression levels, which maps closely onto how the exam separates fundamentals from networking from endpoints.

What Does Data-Centric Security Add to a Network Exam?

Data-centric security is a separate objective covering reverse proxies, web application firewalls, database firewalls and database activity monitoring, and it pairs with a data discovery and governance objective covering file classification, data loss prevention, database governance and mobile device management. Together they move the exam from protecting paths to protecting the thing at the end of them.

The logic follows from presumption of compromise. If you assume an attacker reaches the internal network, controls that only guard the route are already bypassed, and what remains is whether the data itself is classified, monitored and constrained. A database firewall and database activity monitoring answer a question a network firewall cannot: not who reached the server, but what they then asked it for.

Classification is the prerequisite nobody wants

File classification and data loss prevention appear together in the objectives for a reason. DLP that does not know what is sensitive produces noise, and classification is the unglamorous work that makes the rest function. The exam treats it as foundational rather than optional, and it is worth knowing the standard classification approaches rather than assuming the tooling decides.

Where Do Cloud and Mobility Fit?

Cloud-based security architecture is one objective, covering cloud security concepts, securing on-premise hypervisors, network segmentation, surface reduction, delivery models and container security. Mobility arrives through mobile device management inside the data governance objective. The framing throughout is hybrid rather than cloud-native, which matches the course title and the reality of most estates.

Note what sits inside that single cloud objective: hypervisor security and container security are both there, alongside delivery models and segmentation. It is a wide objective, and the segmentation and surface reduction elements connect directly back to the Zero Trust networking material rather than standing apart from it.

The hybrid emphasis is deliberate

A cloud-only architecture exam would not need Layer 1 defence or on-premise hypervisor hardening. GDSA keeps both because the architectures it certifies are almost always partly legacy, and the difficult design problems live at the joins. Someone who has only worked in one environment will find the connective questions harder than either half alone.

Who Is GDSA Actually For?

GDSA suits an experienced defender moving from operating controls to designing them: a network security engineer, a blue team lead, or a security architect who needs the design case validated. GIAC sets no formal prerequisites, but the breadth from switching security to container security assumes real operational history across several of those areas.

The absence of a prerequisite is not an invitation. Thirteen objectives spanning Layer 1 to cloud, with a $999 attempt fee, punish anyone treating this as an entry point. A candidate whose experience is concentrated in one layer will find that the exam keeps asking how their layer interacts with the ones they have not worked in.

Where it sits against other GIAC credentials

GDSA is a design credential rather than an operations or forensics one, which is the axis that separates it from most of the GIAC catalogue. If your interest is in what happened after an incident rather than how the estate should have been built, a forensics-oriented credential is the better fit, and the GCFA career case covers that side of the decision.

The training route

The associated course is SANS SEC530, Defensible Security Architecture and Engineering. It is not mandatory, since GIAC certifications can be attempted without the course, but the objectives map to it closely enough that self-study means assembling equivalent coverage yourself across thirteen fairly specific areas. The SEC530 course outline is the clearest available statement of what the exam expects in practice.

How Do You Prepare With No Published Weightings?

GIAC publishes no percentage weightings for GDSA’s thirteen objectives, so there is no small domain to write off and no large one to over-invest in. Plan for even coverage, then let the 63 percent pass mark do the arithmetic: you can afford to be weak in roughly a third of the material, but not absent in any of it.

The thirteen GDSA exam objectives grouped into network stack, network defence, zero trust, and data and cloud
  1. Start with the fundamental security architecture concepts objective, because presumption of compromise and the Zero Trust model frame every other topic on the list.
  2. Work the three Zero Trust objectives next as a single block, since fundamentals, networking and endpoints overlap heavily and studying them apart wastes the connections.
  3. Take the network stack in order after that, Layer 1 and 2, then Layer 3, then IPv6, so the attacks build on the addressing knowledge rather than preceding it.
  4. Cover the data-centric and governance objectives together, treating classification as the prerequisite that makes data loss prevention coherent.
  5. Finish with cloud and mobility, then build and index the reference material you intend to carry, testing it against timed questions at 96 seconds each.

The indexing step is not optional preparation advice for an open book exam of this breadth. Thirteen subject areas across two hours means the difference between a good index and a bad one is several questions, and the material you can look up is the material you do not need to memorise. The same discipline applies to how you practise, which is covered in these GDSA preparation notes.

The objective most people skip

IPv6, almost every time, on the reasonable-sounding grounds that the estate does not use it. It is a full objective out of thirteen, which makes it worth roughly eight percent of the named subject matter, and dual stack means the estate probably does use it whether anyone intended that or not.

Frequently Asked Questions

How many questions are on the GDSA exam?

75 questions, with a two hour time limit. That works out at roughly 96 seconds per question.

What is the GDSA passing score?

63 percent. GIAC set that figure through a psychometric standard-setting study, and it applies to exam versions released on or after 3 August 2019.

How much does GDSA cost?

$999 USD for a certification attempt.

Are there prerequisites for GDSA?

GIAC sets no formal prerequisites. In practice the objectives span switching security through to container security, so real operational experience across several of those areas is assumed.

How many objectives does GDSA have, and how are they weighted?

Thirteen objectives, and GIAC publishes no percentage weightings for them. The list is unordered and unweighted, so even coverage is the only sound strategy.

Can you take the GDSA exam remotely?

Yes. All GIAC exams are web-based and proctored, with two routes: remote proctoring through ProctorU, or onsite proctoring at a Pearson VUE test centre.

How long do you have to sit the exam after buying it?

120 days from the date the attempt is activated in your GIAC account.

Do you have to take SANS SEC530 to sit GDSA?

No. The course is the associated training path and maps closely to the objectives, but the certification can be attempted without it.

Is GDSA a Zero Trust certification?

Substantially, yes. Four of the thirteen objectives are explicitly Zero Trust topics, and the associated course carries Zero Trust in its title, though the exam also covers Layer 1 to Layer 3 defence, IPv6 and data-centric controls.

What is the difference between GDSA and an operations-focused credential?

GDSA certifies design. It asks how an estate should be built so that a compromise is contained, rather than how to run controls day to day or investigate an incident afterwards.

Conclusion

Defensible security architecture is a design discipline built on the assumption that prevention will eventually fail, and GDSA tests that discipline across an unusually wide span: thirteen objectives running from VLAN hopping and ARP cache poisoning up through IPv6, proxies and encrypted remote access to container security and mobile device management, with Zero Trust as the thread connecting them.

The absence of published weightings is the detail that should shape your preparation. With no percentages, 75 questions and a 63 percent pass mark, there is no area you can safely ignore and no shortcut through the list. Group the thirteen objectives into the stack, Zero Trust, and data, index your references properly before the day, and give IPv6 the attention almost everyone else skips.

Rating: 5 / 5 (1 votes)