
GIAC Global Industrial Cyber Security Professional
Domain 3Objective 1
Hardening & Protecting Endpoints GICSP Practice Questions (Page 8)
Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 36–40
- 36
An OT security analyst notices unusual outbound connections from a PLC programming workstation to an external IP address. The workstation runs a host-based firewall and antivirus. What is the first step to investigate this potential incident?
Select an answer first - 37
A food processing plant has a historian server that collects data from PLCs. The server is not patched because the vendor has not validated any updates. The security team wants to detect if the server is being used as a pivot point. Which monitoring approach is most effective for this purpose?
Select an answer first - 38
A chemical plant has a mix of Windows and Linux endpoints. The security team wants to implement a consistent hardening standard. What is the first step in developing a secure configuration baseline?
Select an answer first - 39
What is the primary purpose of endpoint monitoring and logging?
Select an answer first - 40
A water utility has a mix of Windows 10 and Windows 7 SCADA HMIs. The vendor has stopped supporting Windows 7, but the HMIs cannot be upgraded until the next scheduled outage. What is the most appropriate immediate action to reduce risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.