Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Global Industrial Cyber Security Professional

Domain 3Objective 3

Risk Based Disaster Recovery & Incident Response GICSP Practice Questions (Page 3)

Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 11–15

  1. 11expert · hard

    After a significant OT security incident, the incident response team completed the post-incident review. The review identified that the incident response plan was outdated and that the disaster recovery plan did not align with the IR plan. Management wants to ensure that these issues are addressed. What is the most effective way to implement the lessons learned?

    Select an answer first
  2. 12expert · hard

    A large manufacturing company is establishing an incident response team. The team will include an incident commander, lead analyst, and communications lead. The company wants to ensure that the team can effectively respond to both IT and OT incidents. What is the most important consideration when defining the roles?

    Select an answer first
  3. 13application · medium

    A pharmaceutical company's OT network is hit by a ransomware attack that encrypts the batch control servers. The incident response team is working to contain the attack, while the disaster recovery team is preparing to restore the batch control servers from backups. What is the MOST important reason for the two teams to coordinate their activities?

    Select an answer first
  4. 14foundation · easy

    In a business impact analysis, what does the recovery time objective (RTO) define?

    Select an answer first
  5. 15application · medium

    A security analyst at a wastewater treatment plant sees multiple failed login attempts on the SCADA system followed by a successful login from an unknown IP address. The analyst suspects a brute-force attack. What is the most appropriate immediate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.