
GIAC Global Industrial Cyber Security Professional
Domain 2Objective 2
Protocols, Communications, & Compromises GICSP Practice Questions (Page 9)
Part of the Threats, Vulnerabilities, and Compromises domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 41–44
- 41
A factory uses EtherNet/IP for control. A security assessment reveals that an attacker could send a malformed EtherNet/IP packet to crash a PLC. Which protocol vulnerability is being exploited?
Select an answer first - 42
A mining company uses PROFIBUS DP for its conveyor control system. A security consultant notes that the protocol has no built-in security features. Which of the following is a common vulnerability that could be exploited?
Select an answer first - 43
A food processing plant uses OPC UA for data exchange between a historian and multiple PLCs. The security team wants to ensure that only the historian can read data and only the engineering workstation can write configuration changes. What is the most appropriate control?
Select an answer first - 44
A water utility uses DNP3 over serial links for legacy RTUs. The security team wants to add integrity protection without replacing the RTUs. Which approach is most practical?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GICSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.