
GIAC Global Industrial Cyber Security Professional
Domain 3Objective 2
ICS Program & Policy Development GICSP Practice Questions (Page 4)
Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 16–20
- 16
A pharmaceutical company is implementing a new ICS security policy that requires all changes to the production line control system to be logged and reviewed. The training department is developing a program for operators and engineers. What is the most important training objective to support this policy?
Select an answer first - 17
In the context of ICS security policy development, what is the purpose of a risk assessment?
Select an answer first - 18
Who is ultimately accountable for the overall success of the ICS security program?
Select an answer first - 19
What is the primary goal of an ICS security awareness program?
Select an answer first - 20
A water utility's ICS security program was developed five years ago. Since then, the utility has added new treatment technologies and connected more systems to the corporate network. The program has not been updated, and a recent risk assessment identified new vulnerabilities. The utility is also facing a new state regulation that requires annual program reviews. Which action best supports continuous improvement while managing limited resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.