
GIAC Global Industrial Cyber Security Professional
Domain 3Objective 2
ICS Program & Policy Development GICSP Practice Questions (Page 3)
Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 11–15
- 11
A water treatment plant is developing a new ICS security policy. The security manager has drafted the policy and is now identifying who should be responsible for enforcing it. Which role is typically accountable for enforcing ICS security policies at the plant level?
Select an answer first - 12
Which stakeholder group is typically responsible for the day-to-day operation and safety of the industrial process, and therefore must be involved in ICS security policy development?
Select an answer first - 13
What is the primary purpose of an Industrial Control System (ICS) security program within an organization?
Select an answer first - 14
Which of the following best describes the scope of an ICS security program?
Select an answer first - 15
A natural gas distribution company is developing a policy for patch management of its ICS assets. The policy must align with the company's regulatory obligations under state pipeline safety rules. What is the first step in developing this policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.