Exit demo GICSP Global Industrial Cyber Security Professional (GICSP) PDF format · free preview

GIAC GICSP - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/gicsp.html

Question 1
Single choice

For application-aware firewalls filtering traffic between trust zones, which of the following policies should be applied to a packet that doesn't match an existing rule?

A.

Default alert

B.

Default deny

C.

Application deny list

D.

Application allow list

Question 2
Single choice

An administrator wants to script the deployment of a security policy, over the network, to a group of workstations not managed by Active Directory.

What tool could be used to accomplish this task?

A.

secedit.exe

B.

secpol.msc

C.

gpedit.msc

Question 3
Single choice

A brewer uses a local HMI to communicate with a controller that opens a pump to move the wort from the boil kettle to the fermentor.

What level of the Purdue model would the controller be considered?

A.

Level 2

B.

Level 1

C.

Level 0

D.

Level 3

E.

Level 4

Question 4
Single choice

How is a WirelessHART enabled device authenticated?

A.

Using a WPA2 pre-shared key entered by an administrator

B.

Using a join key to send an encrypted request for the shared network key

C.

Using the vendor hard-coded master key to obtain a link key

D.

Using a PIN combined with the device MAC address

Question 5
Single choice

Which type of process is described below?
A fermentor's glycol jacket must maintain a steady temperature during and between batches of beer.

A.

Continuous

B.

Manual

C.

Discrete

D.

Batch

Question 6
Single choice

What kind of data could be found on a historian?

A.

Information needed for billing customers

B.

Information for supervising lower-level controllers in real-time

C.

Diagrams depicting an overview of the process

D.

Runtime libraries that software programs use

Question 7
Single choice

Which of the following can an attacker gain by obtaining PLC logic project files for a SCADA system?

A.

Data regarding personnel and hiring practices

B.

Details about the network architecture

C.

Information about operational firewall rulesets

D.

Schedule of vendor product releases

Question 8
Single choice

Which control helps prevent threats to Integrity?

A.

Firewall egress filtering

B.

Logging IDS alerts

C.

Centralized LDAP authentication

D.

Implementing digital signatures

Question 9
Single choice

What mechanism could help defeat an attacker's attempt to hide evidence of his/her actions on the target system?

A.

Attack surface analysis

B.

Application allow lists

C.

Sandboxing

D.

Centralized logging

Question 10
Single choice

An attacker has a goal of obtaining information stored in an ICS.

Why might the attacker focus his efforts on the operating system rather than the ICS application?

A.

Organizations generally do not define a role or responsibility for dealing with operating systems, leaving them neglected and vulnerable

B.

The operating system will have fewer vulnerabilities than the ICS application

C.

The ICS is more likely to have vendor-provided security hardening guidance than the operating system will

D.

Control of the operating system offers access to applications running on it

Showing 10 of 87 questions · Unlock the full set