Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Global Industrial Cyber Security Professional

Domain 3Objective 3

Risk Based Disaster Recovery & Incident Response GICSP Practice Questions (Page 9)

Part of the Security Management and Response domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 41–45

  1. 41application · medium

    A natural gas pipeline operator has developed a disaster recovery plan and an incident response plan. The plans have never been tested. Management wants to validate the plans without disrupting live operations. What is the MOST appropriate exercise type to conduct first?

    Select an answer first
  2. 42application · medium

    During a cyber incident at a wastewater treatment plant, the incident commander is coordinating the response. The lead analyst has identified the malware and is working on eradication. The communications lead is preparing a statement for the public. Who is responsible for ensuring that the public statement does not reveal sensitive operational details that could aid attackers?

    Select an answer first
  3. 43application · medium

    After a cyber incident at a natural gas pipeline, the incident response team completed eradication and recovery. The operations manager wants to ensure the same type of incident does not happen again. What is the most important action to take?

    Select an answer first
  4. 44application · medium

    A manufacturing company has separate disaster recovery (DR) and incident response (IR) plans. During a ransomware incident, the IR team contains the spread, but the DR team is unsure when to activate the recovery site. What is the best way to ensure coordinated response?

    Select an answer first
  5. 45expert · hard

    A cyber incident at a food processing plant has caused the loss of visibility into the production line's safety interlocks. The incident response team is considering whether to shut down the line. The plant manager is concerned about the cost of a shutdown, while the safety officer is concerned about the risk of an unsafe condition. The incident commander must decide. What is the MOST appropriate decision-making approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GICSP” is a trademark of its owner, used for identification only.