Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Global Industrial Cyber Security Professional

Domain 1Objective 4

PERA Level 2 & 3 Technology Overview and Compromise GICSP Practice Questions (Page 4)

Part of the ICS Fundamentals and Architecture domain, which makes up ~40% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~28–48 in this domain), expect 7–12 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 16–20

  1. 16expert · hard

    An attacker has compromised a Level 3 MES and is sending false production orders to a Level 2 SCADA system. The SCADA system is executing these orders, causing physical equipment to operate outside safe parameters. What is the most critical impact of this compromise?

    Select an answer first
  2. 17application · medium

    A pharmaceutical plant uses a Level 3 historian to store batch records for regulatory compliance. The historian is connected to the corporate network for reporting. A ransomware attack encrypts the historian's database. What is the most significant consequence for the plant?

    Select an answer first
  3. 18application · medium

    A plant's Level 3 historian is being decommissioned. The plant must retain historical data for regulatory compliance. What is the best action?

    Select an answer first
  4. 19application · medium

    A power generation facility has a Level 2 HMI that is used to control turbine speed. The HMI is connected to the corporate network for remote monitoring. An attacker exploits a vulnerability in the HMI's web interface and gains control. What is the most likely immediate action the attacker will take?

    Select an answer first
  5. 20expert · hard

    A pharmaceutical plant's Level 3 MES is integrated with a laboratory information management system (LIMS) for quality data. The integration uses a web service that is accessible from the IT network. A penetration test reveals that the web service is vulnerable to SQL injection. What is the best remediation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.