Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Critical Infrastructure Protection (GCIP)

GCIPGIAC Critical Infrastructure Protection

The GIAC Critical Infrastructure Protection (GCIP) certification validates the skills of practitioners who access, support, and maintain critical systems, with a focus on the North American Electric Reliability Corporation's Critical Infrastructure Protection (NERC CIP) standards. It bridges compliance with operational defense, equipping holders with practical implementation strategies to protect power and other critical environments. Earning GCIP demonstrates you understand regulatory requirements and can apply them to keep the grid running securely.

501 practice questions · Updated 2026-07-30

5Domains
12Objectives
68Concepts
501Questions

GCIP Curriculum

Every domain, objective, and concept the GCIP exam measures.

NERC CIP Terms and Definitions

6 concepts · 43 questions
  1. BES Definition
  2. NERC Definition
  3. CIP Definition
  4. Key CIP Terms
  5. CIP Standard Categories
  6. Regulatory Context

Standards Enforcement

6 concepts · 45 questions
  1. Audit Preparation
  2. Enforcement Treatment
  3. Reliability Standards Auditor Worksheet
  4. Reliability Assurance Initiative
  5. Interactive Remote Access
  6. Internal Controls Evaluation

Security Management Controls

3 concepts · 43 questions
  1. Senior Manager Requirements
  2. Security Policies
  3. Low Facility Requirements

BES Cyber System Categorization

5 concepts · 16 questions
  1. Attachment 1 Criteria
  2. Operational Effects and Impacts
  3. NERC Functional Model
  4. BES Reliability Operating Services
  5. BES Cyber Asset Identification

Electronic Security Perimeter(s)

8 concepts · 49 questions
  1. Electronic Security Perimeter Architecture
  2. External Routable Connectivity Communication
  3. Access Rules
  4. Dial-Up Access
  5. Malicious Communication Detection
  6. Intermediate Systems
  7. Interactive Remote Access
  8. Multi-factor Authentication

System Security Management

7 concepts · 49 questions
  1. Port and Service Management
  2. Patch Management
  3. Malicious Code Prevention
  4. System Logging
  5. Authentication Requirements
  6. Account Management
  7. Monitoring and Alerting

Physical Security of BES Cyber Systems

6 concepts · 44 questions
  1. Physical Security Plan
  2. Physical Access Controls
  3. Visitor Control Program
  4. Maintenance and Testing of Physical Security
  5. Monitoring of Physical Security
  6. Logging and Alerting for Physical Security

Personnel & Training

4 concepts · 45 questions
  1. Awareness Program
  2. Cybersecurity Training Program
  3. Personnel Risk Assessment
  4. Access Management Program

  1. Change Management Process
  2. Configuration Monitoring
  3. Vulnerability Assessment Fundamentals
  4. Transient Cyber Assets
  5. Removable Media Controls
  1. Incident Response Plan Components
  2. Incident Response Plan Development
  3. Incident Response Plan Testing Methods
  4. Incident Response Plan Exercise Execution
  5. Incident Response Plan Testing Evaluation
  6. Incident Response Plan Reporting Requirements
  7. Incident Response Reporting Procedures
  8. Incident Response Plan Continuous Improvement

Recovery Plans for BES Cyber Systems

4 concepts · 34 questions
  1. Recovery Plan Purpose and Components
  2. Recovery Plan Testing and Exercise Methods
  3. Recovery Plan Testing Frequency and Triggers
  4. Recovery Plan Reporting Requirements

Information Protection

6 concepts · 40 questions
  1. Information Protection Program Overview
  2. Information Identification
  3. Information Classification
  4. Information Protection Measures
  5. Information Disposal
  6. Information Reuse
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCIP, so none is invented.