
GIAC Global Industrial Cyber Security Professional
Domain 2Objective 1
Intelligence Gathering & Threat Modeling GICSP Practice Questions (Page 4)
Part of the Threats, Vulnerabilities, and Compromises domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 16–20
- 16
A refinery has limited budget for OT security improvements. A risk assessment identified two high-risk findings: (1) unauthenticated access to the engineering workstation's remote desktop service, and (2) lack of monitoring on the process control network. The plant manager wants to address the finding with the highest residual risk after mitigation. Which approach should the security team recommend?
Select an answer first - 17
A vulnerability scan of a water utility's OT network identifies that the HMI software has a known remote code execution vulnerability. The vendor has released a patch, but the utility cannot apply it immediately because the HMI is critical and cannot be rebooted. Which compensating control should be implemented first?
Select an answer first - 18
A security assessor is mapping the attack surface of a chemical plant. The plant has a corporate network, a DMZ with a data historian, and an OT network with PLCs and HMIs. Which of the following is the most significant attack surface expansion that should be documented?
Select an answer first - 19
A security team is analyzing a cyber incident at a wastewater treatment plant. The attackers used publicly available exploit code for a known vulnerability in the plant's SCADA software, and the attack was opportunistic rather than targeted. Which threat actor profile is most consistent with this incident?
Select an answer first - 20
A security team is profiling a threat actor that has been observed using stolen credentials to access a utility's VPN, then moving laterally to the OT network and modifying setpoints on a PLC. The actor's actions were precise and caused minimal disruption. Which threat actor profile is most likely?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.