
GIAC Global Industrial Cyber Security Professional
Domain 3Objective 2
ICS Program & Policy Development GICSP Practice Questions (Page 5)
Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 21–25
- 21
A power utility has a security awareness training program that is identical to the corporate IT training. OT staff are required to complete it annually, but they report that it is not relevant to their work. As a result, they do not retain the information, and several recent incidents involved OT staff falling for phishing emails. Which approach best improves the training program?
Select an answer first - 22
A large electric utility that operates a bulk electric system (BES) is updating its ICS security program. The compliance team wants to ensure the program meets mandatory reliability standards. Which set of requirements must the program incorporate?
Select an answer first - 23
A chemical plant is developing its ICS security program. The plant's risk assessment identified that a cyber incident could cause a toxic release. The safety department wants to ensure that security controls do not interfere with emergency shutdown systems. How should the security program integrate risk management to address this concern?
Select an answer first - 24
A utility has adopted a new ICS security policy that requires all operators to use multi-factor authentication (MFA) when accessing the HMI. The training department is designing an awareness program. What is the most important element to include in the training to support this policy?
Select an answer first - 25
A regional water utility is establishing an ICS security program. The utility is not a bulk electric system operator but must comply with state drinking-water regulations and is considering ISA/IEC 62443 as a framework. The board has asked for a document that defines the program's boundaries, the systems in scope, and the key stakeholders. Which document should the security manager produce first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.