GIAC G2700 考試概覽:
| 認證廠商: | GIAC |
|---|---|
| 考試名稱: | GIAC ISO-2700 認證專家考試 |
| 考試代碼: | G2700 |
| 及格分數: | 70% |
| 實際考試題數: | 150 |
| 支援語言: | English |
| 考試費用: | $999 USD |
| 考試形式: | 選擇題, 線性出題, 開卷考試 |
| 考試時間: | 240 分鐘 |
| 相關認證: | ISO/IEC 27001 內部稽核員 ISO/IEC 27001 主導建置師 |
| 證照有效期限: | 4 年 |
| 推薦課程: | SANS MGT512:管理者必備資安領導能力 SANS MGT527:ISO 27001 ISMS 建置實務 |
| 考試報名: | Kryterion 考場資訊 GIAC 官方報名管道 |
| 範例考題: | GIAC G2700 範例考題 |
| 考試方式: | 線上遠端監考,或於 Kryterion / Pearson VUE 考場實體應考 |
| 必備條件: | 無正式報考資格限制 |
| 官方大綱網址: | https://www.giac.org/certifications/certified-iso-27000-specialist-g2700 |
GIAC G2700 考試大綱主題:
| 章節 | 權重 | 目標 |
|---|---|---|
| 風險管理 | 20% | - 風險評鑑與分析方法 - ISO/IEC 27005 架構 - 風險處理與控制措施選定 |
| 資訊安全管理系統概念 | 20% | - 組織環境與利害關係人 - ISMS 之目的、範疇與原則 - ISO/IEC 27000 系列標準概述 |
| ISMS 運作、監控與持續改善 | 20% | - 營運持續與法規遵循 - 管理階層審查與持續改善 - 績效衡量與內部稽核 - 建置執行與文件化 |
| 資訊安全控制措施 | 25% | - 人力資源安全 - 實體與環境安全 - 作業與通訊安全 - 資產管理 - 存取控制 - 資訊系統之建置與開發 |
| ISMS 領導與政策 | 15% | - 角色、職責與問責機制 - 管理階層承諾與內外溝通 - 資訊安全政策之訂定 |
最新的 GIAC Information Security G2700 免費考試真題:
問題 #1
John works as an IT Technician for uCertify Inc. One morning, John receives an e-mail from the company's Manager asking him to provide his logon ID and password, but the company policy restricts users from disclosing their logon IDs and passwords. Which type of possible attack is this?
A. DoS
B. Replay attack
C. Social engineering
D. Trojan horse
問題 #2
Which of the following Acts is a federal law enacted in the United States to control the ways that financial institutions deal with the private information of individuals?
A. Privacy Act
B. Gramm-Leach-Bliley Act
C. Equal Credit Opportunity Act
D. Stalking Amendment Act (1999)
問題 #3
You work as a Security Administrator for uCertify Inc. You are working on a disaster recovery plan. According to the plan, the remote site B will hold a copy of data that is 2 hours behind the production data at site A.
It will take 4 hours after a downtime at site A to decide to shift production to site B.
An additional 40 minutes will be needed to bring up the network and redirect users so that the site B can become productive. What is the RPO of the plan?
A. 4 hours
B. 50 minutes
C. 40 minutes
D. 2 hours
問題 #4
John works as a Security Administrator for uCertify Inc. As per his past experience, he wants to make a policy stating that any hardware devices containing information about the organization should be destroyed properly before they are thrown. After applying this policy, John will be able to ensure that the information on the devices will not fall into the hands of unauthorized persons after properly discarding the devices. Which of the following types of policies is John going to create?
A. Due Care
B. Privacy
C. Security
D. Disposal and destruction
問題 #5
Mark works as a Webmaster for Infonet Inc. He sets up an e-commerce site. He wants to accept online payments through credit cards on this site. He wants the credit card numbers to be encrypted. What will Mark do to accomplish the task?
A. Use SET.
B. Use HTTP.
C. Use PGP.
D. Use MIME.
問題與答案:
| 問題 #1 答案: C | 問題 #2 答案: B | 問題 #3 答案: D | 問題 #4 答案: D | 問題 #5 答案: A |

下載最新試用版
851位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








118.163.121.* -
你們的服務和題考古題都不錯,幫助我通過了這次的考試,G2700考試真的很難,還好有你們的幫助,謝謝!