GIAC GDSA 考試概覽:
| 認證廠商: | GIAC |
|---|---|
| 考試名稱: | GIAC 可防禦式安全架構師(GDSA)考試 |
| 考試代碼: | GDSA |
| 證照有效期限: | 4 年 |
| 支援語言: | English |
| 考試時間: | 120 分鐘 |
| 考試費用: | 2,499 美元 |
| 及格分數: | 63% |
| 考試形式: | 線上監考式考試, 選擇題, 情境導向題目 |
| 實際考試題數: | 75 |
| 相關認證: | GIAC Cloud Security Automation (GCSA) GIAC Security Essentials (GSEC) GIAC Network Security Operations (GNSO) |
| 推薦課程: | SANS SEC530:可防禦式安全架構與工程設計 |
| 考試報名: | GIAC 官方報名管道 |
| 範例考題: | GIAC GDSA 範例考題 |
| 考試方式: | 線上監考式考試;可透過 ProctorU 進行遠端監考,或至 Pearson VUE 考場現場應試 |
| 必備條件: | 建議具備:2 年以上資安領域實務經驗,或取得 GIAC 基礎等級認證;熟悉網路安全、安全營運及風險管理相關框架 |
| 官方大綱網址: | https://www.giac.org/certifications/defensible-security-architecture-gdsa |
GIAC GDSA 考試大綱主題:
| 章節 | 權重 | 目標 |
|---|---|---|
| 主題 1: 第一層/第二層防禦 | 10% | - 交換器基礎架構安全 - VLAN 區隔與保護機制 - ARP 欺騙與廣播流量管控 |
| 主題 2: 安全架構基礎概念 | 20% | - 入侵攻擊鏈與鑽石模型之應用 - 安全架構框架與風險評估 - Software Defined Networking (SDN) 安全防護 - Zero Trust Model 之原則與實作 |
| 主題 3: 以資料為中心的安全防護 | 20% | - 加密策略與金鑰管理機制 - 資料庫活動監控與安全防護 - 反向代理伺服器與 WAF 之建置導入 - 資料權杖化與資料遮罩技術 |
| 主題 4: 資料探索、治理與行動管理 | 15% | - 資料分類與盤點作業 - 資料生命週期保護與法規遵循 - Data Loss Prevention (DLP) 之設計與部署 - Mobile Device Management (MDM) 與終端裝置安全 |
| 主題 5: 雲端安全架構 | 20% | - 虛擬化平台與容器安全防護 - 雲端存取控制與身分識別管理 - 雲端服務模式與責任共擔模型 - 雲端網路區隔與微分段技術 |
| 主題 6: 第三層基礎防禦 | 15% | - IPv6 安全考量與控制措施 - Bogon 過濾與路由驗證 - SNMP、NTP 及其他核心服務之安全強化 - CIDR、路由協定與攻擊緩解措施 |
最新的 GIAC Cyber Defense GDSA 免費考試真題:
問題 #1
Which of the following best describes host hardening in a Zero Trust Endpoint framework?
Response:
A. Installing multiple antivirus solutions on each host
B. Implementing strict access controls and reducing unnecessary functionalities on the host
C. Increasing the number of end-user privileges
D. Ensuring all endpoints are physically secure
問題 #2
What are effective countermeasures against VLAN hopping attacks?
(Choose two)
Response:
A. Enabling DHCP snooping on all VLANs
B. Disabling unused ports
C. Setting a native VLAN ID different from data VLANs
D. Implementing VLAN trunking on all switches
問題 #3
In the context of Zero Trust Endpoints, why is end-user privilege reduction considered a critical practice?
Response:
A. It minimizes the risk of accidental data deletion by users
B. It reduces the attack surface by limiting access to critical resources
C. It allows users to install any required software without IT intervention
D. It ensures all users have admin privileges for transparency
問題 #4
Which of the following is the primary function of a web proxy?
Response:
A. Preventing unauthorized users from accessing the network
B. Monitoring and blocking email-based phishing attacks
C. Filtering and managing web traffic between users and the internet
D. Encrypting all data in transit
問題 #5
Which of the following are key features of a next-generation firewall (NGFW)?
(Choose two)
Response:
A. Application awareness and control
B. Deep packet inspection
C. Full disk encryption for all network devices
D. IP address filtering only
問題與答案:
| 問題 #1 答案: B | 問題 #2 答案: B,C | 問題 #3 答案: B | 問題 #4 答案: C | 問題 #5 答案: A,B |

下載最新試用版
851位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








218.104.49.* -
你們的服務和題考古題都不錯,幫助我通過了這次的考試,GDSA考試真的很難,還好有你們的幫助,謝謝!