Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Global Industrial Cyber Security Professional

Domain 2Objective 1

Intelligence Gathering & Threat Modeling GICSP Practice Questions (Page 2)

Part of the Threats, Vulnerabilities, and Compromises domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 6–10

  1. 6application · medium

    A security engineer is analyzing the attack surface of a building automation system (BAS) that controls HVAC and lighting. The BAS has a web interface accessible from the corporate network, and the controller uses BACnet/IP on the OT network. Which of the following is the most critical attack surface to address?

    Select an answer first
  2. 7application · medium

    An ICS risk assessment identifies two threats: a worm that could disrupt the entire plant's operations, and a phishing campaign that could compromise a single operator's credentials. The worm has a low likelihood but high impact, while the phishing campaign has a high likelihood but low impact. Using a standard risk matrix, which threat should be prioritized for mitigation?

    Select an answer first
  3. 8expert · hard

    A security architect is applying the PASTA threat modeling methodology to a new cloud-based SCADA system. The architect has identified that the system uses a public API for data exchange. Which of the following is the most appropriate next step in the PASTA process?

    Select an answer first
  4. 9application · medium

    A penetration tester is conducting a red team exercise against an electric utility. The tester wants to identify the make and model of the substation's protective relays without being detected by the SOC. Which intelligence gathering method is most likely to avoid detection?

    Select an answer first
  5. 10application · medium

    An ICS security team is using the STRIDE threat modeling framework to evaluate a new remote access solution for their control network. They have identified that an attacker could spoof a legitimate engineer's credentials to gain access. Which STRIDE category does this threat fall under, and what is the most appropriate mitigation to prioritize?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.