Browse all practice questions for the SANS Global Industrial Cyber Security Professional (GICSP) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GICSP Practice Test 2026 – Complete Study Resource course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What vulnerability level is represented by Stratum 16?
  • What type of access does a vulnerability of controllers and field devices NOT typically include?
  • What does the term 'checksums' refer to in software installation controls?
  • Which of the following describes a VLAN (Virtual Local Area Network)?
  • What impacts the signal quality of satellite communications in VSAT systems?
  • What was a key vulnerability of WEP security in WiFi?
  • Which PLC programming language is known to be difficult to troubleshoot?
  • Which of the following is NOT a property of a message digest?
  • What does a patch typically address?
  • Which type of attacks is a concern with Bluetooth during the pairing process?
  • What is the purpose of a Process Hazard Analysis (PHA)?
  • Which of the following utilities primarily utilizes the DNP3 protocol?
  • What is an example of a symmetric encryption algorithm?
  • Which option best describes the "Act" phase in the PDCA cycle?
  • What is defined as a Baseline Configuration?
  • What follows the Eradication step in the incident handling process?
  • In RAID level 1, what technique is primarily used?
  • Which of the following devices requires physical protection in an ICS?
  • In the context of encryption algorithms, what does the term "key" refer to?
  • What occurs during DNS cache poisoning?
  • Which of the following best defines a trapdoor function in cryptography?
  • Which company developed the Ethernet/IP protocol?
  • Which class of cipher is typically used in software and has reusable keys?
  • What is the function of the public key in the context of digital signatures?
  • Which technology does WirelessHART leverage for its PHY/MAC layer?
  • What is a key characteristic of UDP?
  • What is a common application of the Take-Grant access control model?
  • What type of attack does 'Evil Twin' refer to in wireless security?
  • What is the key technique used in a Spoofing attack?
  • Which of the following is a function of a Database Activity Monitor (DAM)?
  • Why is the hashing function critical for non-repudiation?
  • Which IEC standard relates to Safety Integrity Levels (SIL)?
  • What does RTP stand for in networking protocols?
  • Which encapsulation type does ISA100.11a utilize for gaining benefits of IPv6?
  • What type of attack exploits the probability of collisions in hash functions?
  • What distinguishes an Incremental Backup from a Differential Backup?
  • What is the primary purpose of the Common Industrial Protocol (CIP)?
  • Which of the following threats is categorized as a deliberate external threat?
  • Which method is commonly used to reduce costs and increase mobility in ICS environments?
  • Which type of account is used to run services or scheduled tasks without user intervention?
  • Which frequency range is NOT associated with VSAT?
  • Which type of backup captures all modified files since the last full backup while preserving the archive attribute?
  • What is one of the major disadvantages of using ICS wireless systems?
  • What is the primary role of a Registration Authority (RA)?
  • What principle ensures that an employee is granted the minimum privileges necessary for their tasks?
  • Which technology adds cryptographic signatures to DNS responses?
  • What factor should be considered regarding off-site data storage?
  • What is a recommended method for detecting rogue access points in a wireless network?
  • What is the acceptable throughput rate for biometrics?
  • What is one function of the PING utility?
  • What is the first step in the ISO27001 process approach?
  • What type of processing capabilities do RTUs typically share with PLCs?
  • What is the primary goal of a directory traversal attack?
  • Which of the following represents a characteristic of a hashing function?
  • What does "keyspace" refer to in a cryptosystem?
  • Which of the following is NOT a stage of data erasure?
  • Which feature is unique about Wireless HART's encryption process?
  • What function does SSL/TLS serve in network security?
  • What is a major vulnerability exhibited by wireless networks using RF jamming?
  • What is a hotfix primarily designed to do?
  • How is network congestion typically managed by TCP?
  • What is the first step in the incident handling process?
  • Which of the following is NOT an active technical control for physical security?
  • What is a unique feature of Wireless HART security?
  • Which term refers to the direct connection of a clock to an atomic clock?
  • Which technology is used for satellite communications in industrial applications?
  • What action does Configuration Control ensure during system implementation?
  • What is a common benefit of centralized guard staff monitoring multiple access points?
  • Which of the following is considered a procedural control in physical security?
  • What is a primary function of ICMP's Type 3?
  • What mechanism does EAP support for wireless authentication?
  • What is the most commonly used stream cipher?
  • What is a characteristic of block ciphers in cryptography?
  • Which of the following is the most common VPN security protocol?
  • Which TCP flag is indicated by the acronym "SYN"?
  • Which statement is true regarding zones in a security context?
  • What is an attack method known as "VLAN hopping"?
  • What is the primary purpose of media sanitation according to NIST SP 800-88?
  • What happens during a collision in cryptography?
  • What is a characteristic of HMAC hashing?
  • What is the main advantage of a stream cipher compared to a block cipher?
  • What does Hierarchical Storage Management (HSM) primarily manage?
  • What does ICCP stand for?
  • What type of messaging does Ethernet/IP use for its implicit messaging?
  • What is a common risk associated with rogue OPC servers?
  • What is a feature of WirelessHART as defined by IEC 62591?
  • What is the purpose of DHCP Snooping in network security?
  • Which grade of Stratum represents a primary time server?
  • Which attack targets hashing functions by finding two messages with the same hash value?
  • Which method is suggested to mitigate wireless eavesdropping?
  • What does 802.1Q refer to in networking?
  • What is the primary difference of end-to-end encryption in comparison to link encryption?
  • In OPC Classic, what is a significant drawback related to firewalls?
  • What is the role of the FIN flag in TCP connection termination?
  • Which of the following is a method to mitigate Denial of Service (DoS) attacks?
  • What role does LDAP serve in a network environment?
  • What characteristic defines an effective cryptosystem?
  • In Mandatory Access Control (MAC), who manages permissions to objects?
  • What does nonrepudiation ensure in a communication process?
  • Which protocol does WiFi Protected Access (WPA) primarily utilize for encryption?
  • Which of the following is considered a management protocol in an ICS environment?
  • Which technique can enhance wireless network security at multiple layers?
  • What risk is associated with the use of rogue access points?
  • What does the term 'translate' refer to in the context of program execution permissions?
  • What does the Bell-LaPadula model primarily focus on?
  • What should security defenses in wireless networks focus on due to inherent vulnerabilities?
  • What is a characteristic of the TCP protocol?
  • What is a characteristic of a 'Hot Site' in data processing continuity planning?
  • Which protocol typically uses UDP Port 53?
  • Data manipulation in an industrial context refers to which of the following actions?
  • What does HART stand for?
  • What is a common tool used to audit network installations for security consistency?
  • What functionality does a Digital Protective Relay (DPR) typically provide?
  • What should be considered when implementing strong wireless LAN security measures?
  • What describes a key characteristic of RF Mesh Networks?
  • What does Forward DNS do?
  • Which of the following descriptions best fits a "conduit"?
  • Which ICMP type signifies a ping request?
  • Which of the following protocols is based on TCP?
  • Which wireless standard was developed by ISA to compete with Wireless HART?
  • What control could be used to restrict software installation based on file extension?
  • Which analysis method serves as a bridge between qualitative and quantitative risk evaluation?
  • Which of the following is a critical element of a staff training program for security awareness?
  • What is the primary goal of a Denial of Service (DoS) attack in the context of industrial control systems?
  • Which frequency range is loosely defined as microwave?
  • What distinguishes the newest methodology for hazard evaluation and risk assessment?
  • What is a session key in cryptography?
  • Which protocol is an example of mutual authentication for wireless security?
  • What is a common feature of file integrity monitoring systems?
  • Which hashing function is noted for having certain constraints according to NIST?
  • What is the purpose of Configuration Control?
  • What is the primary purpose of ICMP?
  • What happens during a graceful TCP session closure?
  • What does the TTL expired message indicate in ICMP?
  • What is an Access Control List (ACL) primarily used for?
  • What does a traceroute command show?
  • Which of the following is NOT a type of Profibus?
  • When are Group Policy Objects (GPOs) typically applied?
  • What can firmware modifications potentially do to an ICS device?
  • In symmetric encryption, what is the key characteristic of the algorithms used?
  • What type of applications does Profibus PA cater to?
  • Which component can be modified to affect the functionality of industrial controls?
  • What is the recommended relative humidity for computer rooms?
  • ISA-12 pertains to what kind of equipment?
  • What type of communication does the ICCP protocol utilize?
  • How does TCP handle out-of-order packets?
  • Which of the following is NOT a commonly recognized subtype of IDS?
  • Which of the following is true about stream ciphers?
  • What does AES represent in the context of block ciphers?
  • What protocol is used for the physical layer in ISA100.11a?
  • What is meant by “Asset Inventory” in zone characteristics?
  • Which ICMP code indicates a host is unreachable?
  • Which layer of the OSI model is Modbus TCP encapsulated in?
  • What type of ports do BOOTP and DHCP utilize for network interface configuration?
  • Which statement is true regarding the security of proprietary protocols?
  • What can be a result of an ICS attack?
  • What does FMS in Profibus stand for?
  • Which access control model allows permissions based on a lattice structure?
  • What is the function of a Default Account in a system?
  • Which type of threat is characterized by a disgruntled employee?
  • What role does the Wireless Industrial Technology Konsortium (WiTECK) play?
  • Which of the following best describes a PLC?
  • In the context of cybersecurity, what does the term "Baseline" imply?
  • What is the Baseline process used for?
  • What is the purpose of using TSIG in DNS?
  • What is a key component in configuration management?
  • Which of the following is recommended for strong authentication on WiFi networks?
  • What technology does OPC utilize for its process control standard?
  • In a TCP session, what does the ACK flag signify?
  • In the context of IPSec, what is the main purpose of the Transport Mode?
  • What is the process of overwriting data media for internal reuse called?
  • Among the following, which is a method for encrypting data on WiFi networks?
  • In public key infrastructure, what is the role of the Repository?
  • What does DNS reverse lookup involve?
  • Which process hazard analysis method involves brainstorming potential failures before taking further actions?
  • What might be an example of file integrity monitoring?
  • What does DNP stand for in networking protocols?
  • What encryption method does Zigbee employ?
  • What is a significant limitation of VSAT systems?
  • What is the primary focus of the encryption process in cryptographic systems?
  • What characteristic defines link encryption?
  • In RF mesh networks, what is the main advantage of using a wireless approach?
  • In configuration management, what is a Configuration Item (CI)?
  • HAZOP, or Hazard and Operability Study, is primarily used for what type of analysis?
  • Which of the following is a key issue in the management of cryptographic keys?
  • Which ISM band is most commonly used in the US?
  • What defines the content of a Configuration Item (CI)?
  • Which of the following describes a software installation control measure?
  • What is a primary use of an asymmetric encryption algorithm?
  • What method is employed if a team cannot reach a decision after conducting a Process Hazard Analysis?
  • Which type of firewalls are designed to validate OPC connection request messages?
  • What is a digital signature primarily used for?
  • What is a key output of conducting a Hazard and Operability Study (HAZOP)?
  • What is a unique characteristic of 'Warm Sites' in data processing continuity planning?
  • What is a significant improvement of WPA2 over WEP?
  • What type of approach does ISO27001 emphasize for managing information security?
  • What is a key management issue associated with the generation of cryptographic keys?
  • What should be fully understood when allowing mobile devices in a workplace (BYOD)?
  • What is the purpose of the Initial Sequence Number (ISN) in TCP?
  • Which method is commonly associated with Social Engineering attacks?
  • Which Python-based framework is associated with Zigbee security?
  • What do inspection parameters in safety analysis primarily focus on?
  • What does the Lessons Learned phase aim to achieve?
  • Which systems is hping compatible with?
  • What is the primary purpose of cryptographic encryption?
  • In what year was the Modbus protocol introduced?
  • In the command 'mount -o remount,nosuid /tmp', what does 'remount' signify?
  • When a cryptosystem is described as 'effective,' it means:
  • Which protocol operates on UDP port 53?
  • Where can encryption typically occur within a network?
  • What is one of the main functions of field controllers?
  • What does OPC stand for in the context of industrial automation?
  • What is the significance of the 2.4GHz ISM band in wireless communications?
  • Which of the following is a recommendation for an effective patch management program?
  • Which of the following is NOT a managed item by Group Policy?
  • What is a 'Cold Site' in the context of Business Continuity Planning?
  • Which team members are typically involved in safety analysis?
  • What should a well-defined training program for security awareness primarily include?
  • What is a critical step in software remediation verification?
  • What unique feature is associated with Merkle-Hellman (Trapdoor) Knapsack cryptography?
  • What type of software is hping classified as?
  • What defines a socket in networking?
  • What does Health, Safety and Environmental (HSE) responsibility primarily focus on?
  • Which of the following is a type of Fieldbus standard?
  • Which of the following is NOT a key element to consider in physical security?
  • What is a Reference Monitor responsible for in a system?
  • Which policy manages NTFS permissions?
  • Which cellular technology vulnerability is mentioned in relation to wireless communication?
  • During a wireless network audit, what should be deleted to enhance security?
  • What is the recommended action for ensuring the longevity and security of cryptographic keys?
  • What is one of the key factors when configuring VSAT for optimal performance?
  • What does Access Reconciliation ensure?
  • Which version of OPC is indicated by the term Unified Architecture?
  • What is the standard port number for Modbus TCP?
  • What are the credentials for logging into Siemens Simatic WinCC?
  • Which step follows Identification in the incident handling process?
  • What does a one-way Security Association (SA) in IPSec allow?
  • Which of the following describes a backdoor in a system?
  • In which domain does the concept of unauthorized access typically result in legal actions?
  • What is considered a best practice for file integrity monitoring?
  • What is meant by key clustering in cryptography?
  • Which model is considered upside down compared to the Bell-LaPadula model?
  • Which communication protocol does DNP3 use by default?
  • What does the "Check" phase in the ISO27001 process approach involve?
  • Which of the following options is a role of the Network Enforcement Zones?
  • What action is essential when a cryptographic key reaches the end of its life?
  • Which of the following statements about conduits is correct?
  • What is Social Engineering primarily concerned with?
  • What is the first phase of the SDLC according to NIST?
  • Which of the following accurately describes the functionality of an Account?
  • How does file integrity monitoring typically perform its task?
  • Which statement accurately describes cryptography?
  • Which of the following best defines a substitution cipher?
  • Which process involves comparing two sets of records for accuracy?
  • Which algorithm is based on factoring prime numbers?
  • What is a significant characteristic of Bluetooth technology?
  • What is the primary advantage of TCP over UDP?
  • What is the function of a Security Information and Event Management (SIEM) system?
  • What is a characteristic of the WirelessHART mesh network?
  • What characterizes a Man-in-the-Middle (MITM) attack?
  • Which layer does Zigbee accommodate security?
  • What is one example of an active technical control in physical security?
  • Which method can be employed to enhance security on VSAT systems?
  • What does “Destination Network Administratively Prohibited” signify in ICMP?
  • What is one of the functions of field components and PLCs under attack?
  • What is the primary focus of incident containment?
  • What is cryptanalysis?
  • Which protocol has a communication method where the slave can report without being requested by the master?
  • What is the purpose of account expiration in access control?
  • Which component is not typically included in what needs to be protected in an Industrial Control System (ICS) environment?
  • What is the primary purpose of time servers in the NTP Clock Stratum?
  • Which UDP port is designated for TFTP?
  • What does Safety Analysis encompass within an industrial setting?
  • What is the function of RTPS in data distribution services?
  • A cryptosystem consists of which of the following?
  • What does the term 'work factor' refer to in cryptography?
  • What is the data rate of 802.11b?
  • Which account provides temporary access without the need for a permanent login?
  • What is a significant characteristic of Role Based Access Control (RBAC)?
  • Which component of PKI is responsible for storing certificates long-term?
  • Which process assessment technique emphasizes systematic evaluations to improve safety?
  • How are data link independence and compatibility achieved in the Common Industrial Protocol?
  • What is the main goal of file integrity monitoring?
  • What is the primary benefit of frequency hopping in RF communications?
  • How does a digital signature ensure authenticity?
  • What feature distinguishes 802.11i in WiFi?
  • Which organization is likely to utilize Mandatory Access Control (MAC)?
  • Which of the following describes how Modbus operates?
  • What does RAID level 5 utilize for data recovery?
  • What distinguishes session hijacking from other attacks like Man in the Middle?
  • What is Windows Server Update Services (WSUS) used for?
  • Which characteristic is associated with the Safety Extension of CIP?
  • Which protocol in IPSec provides encryption and limited authentication?
  • What is one outcome of performing Configuration Auditing?
  • Which access control policy allows the owner of a file to determine access privileges?
  • What happens during key disposal in cryptography?
  • What is a key function of an RTU compared to a PLC?
  • Unauthorized access occurs when?
  • What does a strong security awareness program focus on?
  • Which RAID level is based on Hamming Code parity?
  • Which of the following can result from a collision?
  • What does cryptography primarily focus on?
  • What does the Common Industrial Protocol (CIP) - Safety Extension add to the standard protocol?
  • What does the TCP header size typically measure?
  • What is the goal of Reverse DNS?
  • What technology is used to ensure secure communication over VSAT networks?
  • What is the recommended approach to educate users regarding wireless security?
  • Which type of disruption refers to a complete shutdown of a facility for a day?
  • What does Configuration Auditing check for?
  • Which frequency band is known as the 900 mHz band?
  • What is the primary function of a Certification Authority (CA) in a Public Key Infrastructure (PKI)?
  • What type of cabling does Profibus utilize for communication?
  • Which format is most popular for public key certificates?
  • Which is NOT a preference when using proprietary wireless communications?
  • Which of the following is NOT a category of media sanitization?
  • Which of the following devices is commonly deployed for Intrusion Detection Systems (IDS) within a network?
  • What is the main disadvantage of using MD5 as a hashing function?
  • What is the purpose of a service pack?
  • What action can be taken to minimize the risks from rogue access points on a network?
  • Which authentication protocol is suggested to minimize masquerading attacks in WiFi?
  • What is a primary security concern with OPC servers?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy