GIAC GICSP Certification Sample Questions

GICSP Dumps, GICSP PDF, GICSP VCE, GIAC Global Industrial Cyber Security Professional VCE, GIAC GICSP PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Global Industrial Cyber Security Professional (GICSP) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GICSP certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GICSP Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual Global Industrial Cyber Security Professional (GICSP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Global Industrial Cyber Security Professional exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GICSP Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GICSP Sample Questions:

01. At a brewery, WirelessHART transmitters on the fermentation tanks began losing readings the week a new 2.4 GHz Wi-Fi access point was installed nearby. A spectrum survey shows heavy Wi-Fi activity overlapping the mesh's channels and no unknown transmitters.
What is the most likely explanation?
a) Coexistence interference from the new access point sharing the 2.4 GHz band
b) Battery depletion across all of the transmitters at once
c) A replay of old transmitter frames from a recorded session
d) Deliberate jamming by an unknown transmitter that is flooding the band with noise
 
02. The board of an electric cooperative asks its OT security manager to show whether the control-system security program is reducing risk. The manager must pick one measure to report each quarter.
Which measure best shows program effectiveness?
a) Number of security policies written and approved by management since launch
b) Total firewall log entries collected per quarter
c) Hours of security training delivered
d) Share of critical controllers with a verified, current offline backup
 
03. An LNG terminal wants wireless versions of its HART pressure transmitters, forming a self-organizing mesh through a gateway. The host system must keep using the same HART commands and device descriptions it already uses for the wired instruments.
Which wireless technology meets this need?
a) ISA100.11a, a separate industrial mesh standard
b) WirelessHART, which extends the HART instrument protocol over a secured mesh
c) Wi-Fi with WPA3 on each transmitter
d) Zigbee, a general low-power 802.15.4 mesh
 
04. In an electric substation, protection relays exchange IEC 61850 GOOSE messages on the station bus to trip breakers within a few milliseconds. During a security test, a laptop plugged into a spare station-bus switch port publishes GOOSE trip messages carrying a feeder relay's identifiers, and the subscribing relay operates its breaker.
What property of GOOSE made this possible?
a) GOOSE is routed over IP, so the laptop reached the relays through the substation router
b) GOOSE depends on a master station polling each relay, so the laptop acted as a rogue master
c) GOOSE is sent as Layer 2 multicast, and in its common form subscribers act on it without authenticating the publisher
d) GOOSE encrypts its payload with one key shared by every relay, which the laptop had recovered
 
05. At a pharmaceutical batch plant, every HMI, engineering workstation and the plant historian log on through a single Windows domain hosted on the control network. An OT security analyst is ranking the Level 2 and Level 3 assets by how much access an attacker would gain from compromising each one.
Which asset would give an attacker administrative logon across all of those hosts at once?
a) The alarm server that notifies operators in each area
b) The control-network domain controller at Level 3 that authenticates every host
c) The plant historian that collects batch data from every area
d) The batch HMI that operators use to start recipes
 
06. During a network redesign at a glass factory, an engineer must decide which servers move to the Level 3 site operations network instead of staying on a Level 2 area network.
Which servers belong at Level 3?
(Choose two.)
a) The alarm server for the forming line
b) The OT security monitoring server that collects events from every area
c) The ERP server that schedules purchasing and shipping
d) The operator HMI server for the furnace area
e) The backup server that stores configurations for control hosts across the site
 
07. In the widely reported 2015 cyberattack on Ukrainian electricity distribution companies, attackers cut power to customers by opening breakers.
How did the attackers open the breakers?
a) Malware rewrote the protective relays' trip logic
b) They took remote control of operators' SCADA workstations and issued open commands
c) Malware spoofed the substations' voltage and current readings
d) They jammed the radio links serving the substations
 
08. An OT security lead at a steel mill needs executive approval and funding for a control-system security program. Executives have rejected earlier proposals that listed unpatched hosts and open ports.
How should the lead frame the next proposal?
a) In terms of the downtime, injuries and equipment damage the program would reduce, with estimated costs
b) As a compliance checklist of standard clauses the mill does not yet meet
c) As a request matching the corporate IT security budget
d) As a list of vulnerability scan results with a severity score for each host
 
09. The SCADA alarm list at a wastewater utility's control center shows these events for an unstaffed lift station:
02:14:07 LS-14 RTU DI-07 CABINET DOOR OPEN
02:14:52 LS-14 RTU CONFIG PORT ACTIVE
No maintenance is scheduled at LS-14 tonight.
Which actions should the control center take?
(Choose two.)
a) Check work orders and permits, then dispatch staff or security to the site
b) Shut down the lift station remotely at once to prevent any tampering
c) Have engineering compare the RTU logic and settings with the known-good backup
d) Cut the RTU's communication link so the intruder cannot reach SCADA
e) Acknowledge and clear the alarm, since door switches often raise false alarms
 
10. A hydroelectric dam's control vendor needs occasional remote access to troubleshoot the turbine governor controls. The site is writing the remote access section of its ICS security policy.
Which requirements should the section include?
(Choose two.)
a) Remote sessions that terminate directly on the governor controllers
b) Access enabled only for an approved request and disabled when work ends
c) An always-on vendor VPN so support can connect without delay
d) Sessions monitored or recorded by site staff while the vendor is connected
e) Session encryption as the only condition for vendor access

Answers:

Question: 01
Answer: a
Question: 02
Answer: d
Question: 03
Answer: b
Question: 04
Answer: c
Question: 05
Answer: b
Question: 06
Answer: b, e
Question: 07
Answer: b
Question: 08
Answer: a
Question: 09
Answer: a, c
Question: 10
Answer: b, d

Note: For any error in Global Industrial Cyber Security Professional (GICSP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (116 votes)