
GIAC Global Industrial Cyber Security Professional
Domain 2Objective 1
Intelligence Gathering & Threat Modeling GICSP Practice Questions (Page 5)
Part of the Threats, Vulnerabilities, and Compromises domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 21–25
- 21
Which type of threat actor is most likely to be motivated by financial gain and may use ransomware to target industrial control systems?
Select an answer first - 22
In risk assessment for an industrial control system, which factor is most critical to consider when prioritizing risks?
Select an answer first - 23
An ICS security team is using the MITRE ATT&CK for ICS framework to model an adversary's behavior. They have identified that the adversary is using a remote access tool to connect to a control server. Which tactic does this behavior map to, and what is the most relevant mitigation?
Select an answer first - 24
A vulnerability assessment of a food processing plant identifies that the PLCs use a proprietary protocol that is not encrypted. The plant's network is segmented, but the engineering workstation is shared with the corporate network. Which of the following is the most significant risk and the most appropriate mitigation?
Select an answer first - 25
In the context of threat modeling, what is the primary purpose of using a structured framework like STRIDE or PASTA?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.