Browse all practice questions for the SANS Global Industrial Cyber Security Professional (GICSP) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Master the Cyber Fortress: 2026 GICSP Practice Test Adventure! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • How does a digital signature ensure authenticity?
  • In the context of IPSec, what is the main purpose of the Transport Mode?
  • What is a significant limitation of VSAT systems?
  • Which IEC standard relates to Safety Integrity Levels (SIL)?
  • Which of the following represents a characteristic of a hashing function?
  • What is a Reference Monitor responsible for in a system?
  • What is the purpose of account expiration in access control?
  • What does RAID level 5 utilize for data recovery?
  • What role does LDAP serve in a network environment?
  • What is the purpose of DHCP Snooping in network security?
  • Which statement accurately describes cryptography?
  • What might be an example of file integrity monitoring?
  • Which characteristic is associated with the Safety Extension of CIP?
  • What action is essential when a cryptographic key reaches the end of its life?
  • What does OPC stand for in the context of industrial automation?
  • In symmetric encryption, what is the key characteristic of the algorithms used?
  • What can be a result of an ICS attack?
  • Which of the following describes a software installation control measure?
  • What mechanism does EAP support for wireless authentication?
  • What is a characteristic of HMAC hashing?
  • What does a one-way Security Association (SA) in IPSec allow?
  • What role does the Wireless Industrial Technology Konsortium (WiTECK) play?
  • What is the primary benefit of frequency hopping in RF communications?
  • What is a recommended method for detecting rogue access points in a wireless network?
  • Which type of threat is characterized by a disgruntled employee?
  • What method is employed if a team cannot reach a decision after conducting a Process Hazard Analysis?
  • What does the term 'checksums' refer to in software installation controls?
  • Which of the following is NOT a type of Profibus?
  • Which of the following threats is categorized as a deliberate external threat?
  • Which RAID level is based on Hamming Code parity?
  • Which of the following is NOT an active technical control for physical security?
  • What functionality does a Digital Protective Relay (DPR) typically provide?
  • What do inspection parameters in safety analysis primarily focus on?
  • Which of the following descriptions best fits a "conduit"?
  • What does the TTL expired message indicate in ICMP?
  • What is the primary purpose of ICMP?
  • What is a characteristic of the WirelessHART mesh network?
  • Which of the following is NOT a managed item by Group Policy?
  • In the command 'mount -o remount,nosuid /tmp', what does 'remount' signify?
  • What is the purpose of a Process Hazard Analysis (PHA)?
  • Which of the following is NOT a stage of data erasure?
  • What control could be used to restrict software installation based on file extension?
  • What impacts the signal quality of satellite communications in VSAT systems?
  • Which of the following protocols is based on TCP?
  • Which of the following describes a backdoor in a system?
  • Which of the following best defines a trapdoor function in cryptography?
  • Which feature is unique about Wireless HART's encryption process?
  • Which communication protocol does DNP3 use by default?
  • What is a primary use of an asymmetric encryption algorithm?
  • What type of communication does the ICCP protocol utilize?
  • What is the primary purpose of the Common Industrial Protocol (CIP)?
  • Which of the following is the most common VPN security protocol?
  • Which method can be employed to enhance security on VSAT systems?
  • What is a hotfix primarily designed to do?
  • Which frequency range is loosely defined as microwave?
  • Which layer of the OSI model is Modbus TCP encapsulated in?
  • What action does Configuration Control ensure during system implementation?
  • Which of the following is a critical element of a staff training program for security awareness?
  • What is a significant improvement of WPA2 over WEP?
  • Which of the following is NOT a commonly recognized subtype of IDS?
  • What happens during a collision in cryptography?
  • Which component can be modified to affect the functionality of industrial controls?
  • Where can encryption typically occur within a network?
  • What is a common risk associated with rogue OPC servers?
  • Which of the following is a recommendation for an effective patch management program?
  • Which of the following options is a role of the Network Enforcement Zones?
  • What is the first step in the ISO27001 process approach?
  • What is a characteristic of a 'Hot Site' in data processing continuity planning?
  • Which of the following is a method to mitigate Denial of Service (DoS) attacks?
  • What is a significant characteristic of Bluetooth technology?
  • What is a characteristic of block ciphers in cryptography?
  • What does Safety Analysis encompass within an industrial setting?
  • Which of the following is a function of a Database Activity Monitor (DAM)?
  • What is an example of a symmetric encryption algorithm?
  • What is a primary security concern with OPC servers?
  • Which of the following is considered a procedural control in physical security?
  • What does HART stand for?
  • What characteristic defines link encryption?
  • Which of the following devices requires physical protection in an ICS?
  • What does ICCP stand for?
  • What does AES represent in the context of block ciphers?
  • Which ICMP type signifies a ping request?
  • What action can be taken to minimize the risks from rogue access points on a network?
  • Which encapsulation type does ISA100.11a utilize for gaining benefits of IPv6?
  • Which type of backup captures all modified files since the last full backup while preserving the archive attribute?
  • What technology is used to ensure secure communication over VSAT networks?
  • What type of cabling does Profibus utilize for communication?
  • What distinguishes the newest methodology for hazard evaluation and risk assessment?
  • What type of attack does 'Evil Twin' refer to in wireless security?
  • When are Group Policy Objects (GPOs) typically applied?
  • Which process assessment technique emphasizes systematic evaluations to improve safety?
  • Which frequency band is known as the 900 mHz band?
  • Why is the hashing function critical for non-repudiation?
  • What does DNP stand for in networking protocols?
  • What is meant by “Asset Inventory” in zone characteristics?
  • What is the primary focus of the encryption process in cryptographic systems?
  • What is a primary function of ICMP's Type 3?
  • What is a unique characteristic of 'Warm Sites' in data processing continuity planning?
  • What should a well-defined training program for security awareness primarily include?
  • What is one example of an active technical control in physical security?
  • Which ICMP code indicates a host is unreachable?
  • What is a key output of conducting a Hazard and Operability Study (HAZOP)?
  • What does DNS reverse lookup involve?
  • What is one function of the PING utility?
  • Which Python-based framework is associated with Zigbee security?
  • What does a patch typically address?
  • What is the recommended relative humidity for computer rooms?
  • What is cryptanalysis?
  • In what year was the Modbus protocol introduced?
  • What does the term 'work factor' refer to in cryptography?
  • How does TCP handle out-of-order packets?
  • Which process hazard analysis method involves brainstorming potential failures before taking further actions?
  • What should be considered when implementing strong wireless LAN security measures?
  • Which authentication protocol is suggested to minimize masquerading attacks in WiFi?
  • What type of access does a vulnerability of controllers and field devices NOT typically include?
  • Which type of disruption refers to a complete shutdown of a facility for a day?
  • Which class of cipher is typically used in software and has reusable keys?
  • What does Hierarchical Storage Management (HSM) primarily manage?
  • What is the main goal of file integrity monitoring?
  • What are the credentials for logging into Siemens Simatic WinCC?
  • What is an Access Control List (ACL) primarily used for?
  • What is the primary purpose of time servers in the NTP Clock Stratum?
  • Which of the following can result from a collision?
  • What is the purpose of the Initial Sequence Number (ISN) in TCP?
  • What does the TCP header size typically measure?
  • What can firmware modifications potentially do to an ICS device?
  • When a cryptosystem is described as 'effective,' it means:
  • What is a session key in cryptography?
  • In configuration management, what is a Configuration Item (CI)?
  • Which of the following is a key issue in the management of cryptographic keys?
  • What is a key management issue associated with the generation of cryptographic keys?
  • Which of the following is considered a management protocol in an ICS environment?
  • Which statement is true regarding zones in a security context?
  • Which protocol has a communication method where the slave can report without being requested by the master?
  • What should be fully understood when allowing mobile devices in a workplace (BYOD)?
  • In Mandatory Access Control (MAC), who manages permissions to objects?
  • Which of the following describes a VLAN (Virtual Local Area Network)?
  • What does a traceroute command show?
  • What is defined as a Baseline Configuration?
  • Which type of firewalls are designed to validate OPC connection request messages?
  • Which option best describes the "Act" phase in the PDCA cycle?
  • Among the following, which is a method for encrypting data on WiFi networks?
  • What is a digital signature primarily used for?
  • What type of messaging does Ethernet/IP use for its implicit messaging?
  • Which method is commonly associated with Social Engineering attacks?
  • What is one of the functions of field components and PLCs under attack?
  • What is a key characteristic of UDP?
  • What is the data rate of 802.11b?
  • What is a common benefit of centralized guard staff monitoring multiple access points?
  • Which frequency range is NOT associated with VSAT?
  • What is a unique feature of Wireless HART security?
  • What does Access Reconciliation ensure?
  • Which organization is likely to utilize Mandatory Access Control (MAC)?
  • What is a significant characteristic of Role Based Access Control (RBAC)?
  • Which of the following describes how Modbus operates?
  • What is the primary goal of a directory traversal attack?
  • In RAID level 1, what technique is primarily used?
  • Which PLC programming language is known to be difficult to troubleshoot?
  • Which of the following accurately describes the functionality of an Account?
  • During a wireless network audit, what should be deleted to enhance security?
  • What is the purpose of a service pack?
  • What protocol is used for the physical layer in ISA100.11a?
  • What does the "Check" phase in the ISO27001 process approach involve?
  • Which ISM band is most commonly used in the US?
  • Which of the following utilities primarily utilizes the DNP3 protocol?
  • What is the recommended approach to educate users regarding wireless security?
  • What defines a socket in networking?
  • What is a key function of an RTU compared to a PLC?
  • What does "keyspace" refer to in a cryptosystem?
  • What is a common feature of file integrity monitoring systems?
  • Which grade of Stratum represents a primary time server?
  • Which technology adds cryptographic signatures to DNS responses?
  • Which is NOT a preference when using proprietary wireless communications?
  • What principle ensures that an employee is granted the minimum privileges necessary for their tasks?
  • Which company developed the Ethernet/IP protocol?
  • What is the primary advantage of TCP over UDP?
  • What is considered a best practice for file integrity monitoring?
  • What characteristic defines an effective cryptosystem?
  • What function does SSL/TLS serve in network security?
  • What does a strong security awareness program focus on?
  • Which protocol typically uses UDP Port 53?
  • What encryption method does Zigbee employ?
  • A cryptosystem consists of which of the following?
  • What is the purpose of using TSIG in DNS?
  • Which attack targets hashing functions by finding two messages with the same hash value?
  • Which technique can enhance wireless network security at multiple layers?
  • What does Forward DNS do?
  • Which technology is used for satellite communications in industrial applications?
  • What is meant by key clustering in cryptography?
  • What type of applications does Profibus PA cater to?
  • Which version of OPC is indicated by the term Unified Architecture?
  • Which type of attacks is a concern with Bluetooth during the pairing process?
  • Which systems is hping compatible with?
  • Which statement is true regarding the security of proprietary protocols?
  • What technology does OPC utilize for its process control standard?
  • In the context of encryption algorithms, what does the term "key" refer to?
  • Which cellular technology vulnerability is mentioned in relation to wireless communication?
  • Which method is commonly used to reduce costs and increase mobility in ICS environments?
  • What is a feature of WirelessHART as defined by IEC 62591?
  • Which format is most popular for public key certificates?
  • Which policy manages NTFS permissions?
  • Which of the following statements about conduits is correct?
  • What is the key technique used in a Spoofing attack?
  • What does cryptography primarily focus on?
  • What is the first phase of the SDLC according to NIST?
  • Which technology does WirelessHART leverage for its PHY/MAC layer?
  • What does 802.1Q refer to in networking?
  • Which account provides temporary access without the need for a permanent login?
  • Which protocol is an example of mutual authentication for wireless security?
  • What is the primary purpose of media sanitation according to NIST SP 800-88?
  • In the context of cybersecurity, what does the term "Baseline" imply?
  • Which of the following is true about stream ciphers?
  • Which of the following best defines a substitution cipher?
  • What does “Destination Network Administratively Prohibited” signify in ICMP?
  • What is the purpose of Configuration Control?
  • What is the primary focus of incident containment?
  • Which of the following is a type of Fieldbus standard?
  • What occurs during DNS cache poisoning?
  • What is one of the major disadvantages of using ICS wireless systems?
  • What is the main advantage of a stream cipher compared to a block cipher?
  • Which access control model allows permissions based on a lattice structure?
  • Which of the following best describes a PLC?
  • What type of software is hping classified as?
  • How is network congestion typically managed by TCP?
  • What type of ports do BOOTP and DHCP utilize for network interface configuration?
  • What is the acceptable throughput rate for biometrics?
  • Which team members are typically involved in safety analysis?
  • Which layer does Zigbee accommodate security?
  • Which algorithm is based on factoring prime numbers?
  • What factor should be considered regarding off-site data storage?
  • What does the Bell-LaPadula model primarily focus on?
  • What distinguishes an Incremental Backup from a Differential Backup?
  • What does RTP stand for in networking protocols?
  • What is the primary goal of a Denial of Service (DoS) attack in the context of industrial control systems?
  • What is the first step in the incident handling process?
  • Which TCP flag is indicated by the acronym "SYN"?
  • Data manipulation in an industrial context refers to which of the following actions?
  • What happens during key disposal in cryptography?
  • What is the function of a Default Account in a system?
  • What is the goal of Reverse DNS?
  • What is the significance of the 2.4GHz ISM band in wireless communications?
  • What is an attack method known as "VLAN hopping"?
  • What is the Baseline process used for?
  • ISA-12 pertains to what kind of equipment?
  • How are data link independence and compatibility achieved in the Common Industrial Protocol?
  • Which model is considered upside down compared to the Bell-LaPadula model?
  • What characterizes a Man-in-the-Middle (MITM) attack?
  • Which access control policy allows the owner of a file to determine access privileges?
  • What is Social Engineering primarily concerned with?
  • What is a common tool used to audit network installations for security consistency?
  • What does Health, Safety and Environmental (HSE) responsibility primarily focus on?
  • Which hashing function is noted for having certain constraints according to NIST?
  • What describes a key characteristic of RF Mesh Networks?
  • Which of the following is NOT a category of media sanitization?
  • What is the role of the FIN flag in TCP connection termination?
  • What is the primary function of a Certification Authority (CA) in a Public Key Infrastructure (PKI)?
  • What is the standard port number for Modbus TCP?
  • Which protocol operates on UDP port 53?
  • What follows the Eradication step in the incident handling process?
  • How does file integrity monitoring typically perform its task?
  • Unauthorized access occurs when?
  • What does nonrepudiation ensure in a communication process?
  • Which of the following devices is commonly deployed for Intrusion Detection Systems (IDS) within a network?
  • What is the primary difference of end-to-end encryption in comparison to link encryption?
  • What does the Common Industrial Protocol (CIP) - Safety Extension add to the standard protocol?
  • What is Windows Server Update Services (WSUS) used for?
  • What is one outcome of performing Configuration Auditing?
  • HAZOP, or Hazard and Operability Study, is primarily used for what type of analysis?
  • What is the recommended action for ensuring the longevity and security of cryptographic keys?
  • Which analysis method serves as a bridge between qualitative and quantitative risk evaluation?
  • Which component is not typically included in what needs to be protected in an Industrial Control System (ICS) environment?
  • What was a key vulnerability of WEP security in WiFi?
  • What is a critical step in software remediation verification?
  • Which type of account is used to run services or scheduled tasks without user intervention?
  • What risk is associated with the use of rogue access points?
  • What does the Lessons Learned phase aim to achieve?
  • Which protocol in IPSec provides encryption and limited authentication?
  • What is one of the key factors when configuring VSAT for optimal performance?
  • In which domain does the concept of unauthorized access typically result in legal actions?
  • In a TCP session, what does the ACK flag signify?
  • What is the process of overwriting data media for internal reuse called?
  • Which term refers to the direct connection of a clock to an atomic clock?
  • What vulnerability level is represented by Stratum 16?
  • What is one of the main functions of field controllers?
  • What is a major vulnerability exhibited by wireless networks using RF jamming?
  • What is a common application of the Take-Grant access control model?
  • What distinguishes session hijacking from other attacks like Man in the Middle?
  • Which of the following is NOT a key element to consider in physical security?
  • What unique feature is associated with Merkle-Hellman (Trapdoor) Knapsack cryptography?
  • What is the function of the public key in the context of digital signatures?
  • Which UDP port is designated for TFTP?
  • What feature distinguishes 802.11i in WiFi?
  • In RF mesh networks, what is the main advantage of using a wireless approach?
  • What should security defenses in wireless networks focus on due to inherent vulnerabilities?
  • Which wireless standard was developed by ISA to compete with Wireless HART?
  • What does FMS in Profibus stand for?
  • In public key infrastructure, what is the role of the Repository?
  • What does the term 'translate' refer to in the context of program execution permissions?
  • What does Configuration Auditing check for?
  • What type of attack exploits the probability of collisions in hash functions?
  • What is the function of RTPS in data distribution services?
  • What is a key component in configuration management?
  • What is the primary purpose of cryptographic encryption?
  • What happens during a graceful TCP session closure?
  • What is the function of a Security Information and Event Management (SIEM) system?
  • Which step follows Identification in the incident handling process?
  • Which protocol does WiFi Protected Access (WPA) primarily utilize for encryption?
  • What type of approach does ISO27001 emphasize for managing information security?
  • In OPC Classic, what is a significant drawback related to firewalls?
  • Which method is suggested to mitigate wireless eavesdropping?
  • What type of processing capabilities do RTUs typically share with PLCs?
  • What is a 'Cold Site' in the context of Business Continuity Planning?
  • Which of the following is recommended for strong authentication on WiFi networks?
  • What is the most commonly used stream cipher?
  • What defines the content of a Configuration Item (CI)?
  • What is the primary role of a Registration Authority (RA)?
  • Which process involves comparing two sets of records for accuracy?
  • Which of the following is NOT a property of a message digest?
  • Which component of PKI is responsible for storing certificates long-term?
  • What is a characteristic of the TCP protocol?
  • What is the main disadvantage of using MD5 as a hashing function?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy