
GIAC Global Industrial Cyber Security Professional
Domain 3Objective 3
Risk Based Disaster Recovery & Incident Response GICSP Practice Questions (Page 2)
Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 6–10
- 6
A regional water utility is updating its disaster recovery plan. The utility's SCADA system monitors and controls water pressure across the network. The BIA identified that a loss of SCADA visibility for more than 30 minutes could lead to unsafe pressure conditions, while the billing system can tolerate up to 24 hours of downtime. The budget allows for only one recovery site. Which recovery strategy should the utility implement?
Select an answer first - 7
A security analyst at a nuclear power plant is investigating a potential intrusion. The analyst has identified suspicious network traffic but is unsure whether it is a false positive. The plant's policy requires that any potential security incident be reported immediately. What is the most appropriate action?
Select an answer first - 8
A food processing plant's batch controller has been infected with malware that is altering recipe settings. The incident response team has contained the controller by isolating it from the network. What should be the NEXT step in the incident response process?
Select an answer first - 9
After a phishing attack compromised an administrative account at a water treatment facility, the incident response team contained the threat and restored operations. The team is now conducting a post-incident review. What is the PRIMARY purpose of this review?
Select an answer first - 10
An oil refinery's safety system logs show repeated failed login attempts from an internal engineering workstation, followed by a successful login at 3:00 AM. The incident response team is activated. The team has confirmed that the workstation is compromised. What should the team do NEXT in the incident response lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.