
GIAC Critical Infrastructure Protection (GCIP)
Domain 1Objective 2
Standards Enforcement GCIP Practice Questions (Page 7)
Part of the Foundations and Governance domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 6–10 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
6concepts
Questions 31–35
- 31
An entity is preparing for a CIP audit and wants to ensure that all required evidence is available. Which step should be taken first?
Select an answer first - 32
A registered entity has been found non-compliant with a CIP standard due to a misconfigured firewall that was not detected by internal controls. The entity has a good compliance history and the violation did not cause a reliability impact. What is the most appropriate enforcement outcome?
Select an answer first - 33
A reliability coordinator is implementing the Reliability Assurance Initiative (RAI) and must decide how to allocate resources. The coordinator has limited staff and must choose between conducting more frequent audits or implementing a data-driven monitoring system. Which approach is more aligned with RAI's methodology?
Select an answer first - 34
A utility is implementing internal controls to ensure ongoing compliance with CIP standards. Which control is most effective for detecting unauthorized changes to critical cyber assets?
Select an answer first - 35
Which of the following is an example of an internal control used to ensure ongoing compliance with CIP standards?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIP” is a trademark of its owner, used for identification only.