Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Global Industrial Cyber Security Professional

Domain 3Objective 2

ICS Program & Policy Development GICSP Practice Questions (Page 9)

Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts

Questions 41–45

  1. 41application · medium

    A mid-sized electric utility that is not a bulk electric system (BES) operator wants to improve its ICS security posture. It is subject to state public utility commission regulations and is considering adopting a recognized standard to guide its program. Which approach best aligns the utility's program with regulatory expectations?

    Select an answer first
  2. 42application · medium

    A hospital is defining the scope of its ICS security program. The hospital has a building management system (BMS) that controls HVAC and elevators, and a separate clinical engineering network for medical devices. The board asks which systems should be included in the ICS security program. What is the best scoping decision?

    Select an answer first
  3. 43application · medium

    An electric cooperative has had an ICS security program for three years. During a recent audit, several controls were found to be ineffective, and the threat landscape has changed significantly. What is the most appropriate action to support continuous improvement?

    Select an answer first
  4. 44application · medium

    A chemical plant is subject to both NERC CIP and ISA/IEC 62443 because it has a large co-generation facility that feeds the bulk power system. The security team is developing a single ICS security program. Which approach best aligns the program with both sets of requirements?

    Select an answer first
  5. 45expert · hard

    A utility has implemented a policy that requires all OT personnel to use a new vendor management system for remote access requests. The policy has been in place for six months, but compliance is low because operators find the system cumbersome. The security manager must improve compliance. What is the most effective approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.