Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Global Industrial Cyber Security Professional

Domain 2Objective 2

Protocols, Communications, & Compromises GICSP Practice Questions (Page 6)

Part of the Threats, Vulnerabilities, and Compromises domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 26–30

  1. 26application · medium

    A natural gas pipeline uses serial Modbus RTU over a leased line to communicate with remote pumps. An attacker gains physical access to the line and splices into it. What is the most likely impact of this communication compromise?

    Select an answer first
  2. 27expert · hard

    A water utility uses Modbus TCP for remote telemetry. The security team discovers that an attacker has been sending Modbus write commands to a pump's PLC, causing it to run at unsafe speeds. They need to stop this immediately without disrupting normal operations. What is the most effective immediate action?

    Select an answer first
  3. 28application · medium

    A water treatment facility uses Modbus TCP between a PLC and an HMI. The network team recently noticed that an engineering workstation on the same VLAN can send arbitrary Modbus function codes to the PLC. Which control would most directly reduce the risk of an attacker exploiting this protocol weakness?

    Select an answer first
  4. 29expert · hard

    A power plant's control network uses IEC 61850 GOOSE messages for protection tripping. The security team wants to detect an attacker injecting fake GOOSE messages that could cause a breaker to open. They have a limited budget and cannot add new hardware. What is the most effective detection method?

    Select an answer first
  5. 30expert · hard

    A refinery has a mix of legacy Modbus TCP and modern OPC UA devices. The security team must implement a solution that provides authentication and integrity for both protocols without changing the PLCs. They also need to maintain real-time performance. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.