Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Global Industrial Cyber Security Professional

GICSP

The GIAC Global Industrial Cyber Security Professional (GICSP) certification validates your ability to secure industrial control systems across IT and OT environments. It bridges expertise in IT, engineering, and cybersecurity, preparing you to protect critical infrastructure throughout the ICS lifecycle. This vendor-neutral, practitioner-focused credential is ideal for professionals who engineer or support control systems and share responsibility for their security.

448 practice questions · Updated 2026-07-30

3Domains
10Objectives
70Concepts
448Questions

GICSP Curriculum

Every domain, objective, and concept the GICSP exam measures.

ICS Components & Architecture

10 concepts · 53 questions
  1. ICS Components Overview
  2. Sensors and Actuators
  3. Controllers (PLC, RTU, DCS)
  4. Human-Machine Interface (HMI)
  5. Communication Protocols and Networks
  6. ICS Architecture Layers
  7. Field Devices and Instrumentation
  8. Control Loop Fundamentals
  9. ICS Data Flow and Integration
  10. Redundancy and Reliability in ICS

ICS Overview & Concepts

7 concepts · 46 questions
  1. ICS Definition and Purpose
  2. ICS Components
  3. ICS vs. IT Systems
  4. ICS Architecture Layers
  5. ICS Communication Protocols
  6. ICS Operational Technology (OT) Environment
  7. ICS Security Challenges
  1. PERA Model Overview
  2. Level 0 Technology
  3. Level 1 Technology
  4. Communication Between Levels 0 and 1
  5. Compromise of Level 0 and 1
  1. PERA Model Overview
  2. Level 2 Technology Components
  3. Level 3 Technology Components
  4. Data Flow Between Levels 2 and 3
  5. Compromise Vectors for Level 2
  6. Compromise Vectors for Level 3
  7. Impact of Compromise on Operations

  1. Intelligence Gathering Methods
  2. Threat Modeling Frameworks
  3. Attack Surface Analysis
  4. Threat Actor Profiling
  5. Vulnerability Identification
  6. Risk Assessment and Prioritization
  1. Protocol Vulnerabilities
  2. Communication Compromises
  3. Attack Vectors in ICS
  4. Mitigation Strategies

Wireless Technologies & Compromises

5 concepts · 34 questions
  1. Wireless Attack Vectors
  2. Wireless Encryption Weaknesses
  3. Wireless Reconnaissance Techniques
  4. Wireless Intrusion Detection
  5. Wireless Security Controls

Hardening & Protecting Endpoints

8 concepts · 48 questions
  1. Endpoint Hardening Fundamentals
  2. Patch Management
  3. Configuration Management
  4. Access Control for Endpoints
  5. Endpoint Monitoring and Logging
  6. Endpoint Protection Tools
  7. Physical Security of Endpoints
  8. Endpoint Lifecycle Management

ICS Program & Policy Development

8 concepts · 51 questions
  1. ICS Program Definition
  2. Policy Development Process
  3. Regulatory and Standards Alignment
  4. Risk Management Integration
  5. Roles and Responsibilities
  6. Policy Implementation and Enforcement
  7. Training and Awareness
  8. Continuous Improvement
  1. Risk-Based Disaster Recovery Planning
  2. Business Impact Analysis (BIA)
  3. Recovery Strategies and Alternatives
  4. Incident Response Lifecycle
  5. Incident Response Team Roles and Responsibilities
  6. Incident Detection and Analysis
  7. Containment, Eradication, and Recovery
  8. Post-Incident Activities and Lessons Learned
  9. Integration of Disaster Recovery and Incident Response
  10. Testing and Exercising Plans
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GICSP, so none is invented.