GIAC · Global Industrial Cyber Security Professional GICSP

GIAC Global Industrial Cyber Security Professional GICSP Exam Practice Questions

78 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 78 questions in this pack

Question 1

For application-aware firewalls filtering traffic between trust zones, which of the following policies should be applied to a packet that doesn't match an existing rule?

  1. Default alert
  2. Default deny
  3. Application deny list
  4. Application allow list
Show answer and explanation

Correct answer: B. Default deny

An application-aware firewall separating trust zones should end its rule base with an implicit or explicit default deny, so any packet that matches no rule is dropped. This enforces least privilege and forces administrators to explicitly authorize every flow that crosses the zone boundary. Default deny gives the most secure baseline and also produces cleaner logging of unexpected traffic.

Why the other options are wrong

  • A. Default alert only generates a notification and still lets unmatched, potentially malicious traffic pass.
  • C. An application deny list blocks only the applications it names, so anything not listed is still allowed through.
  • D. An application allow list describes which applications are permitted by rule, but the question asks for the action taken when no rule matches at all.

Question 2

An administrator wants to script the deployment of a security policy, over the network, to a group of workstations not managed by Active Directory. What tool could be used to accomplish this task?

  1. secedit.exe
  2. secpol.msc
  3. gpedit.msc
Show answer and explanation

Correct answer: A. secedit.exe

secedit.exe is the command line security configuration tool that applies a security template to a system, so it can be called from a script and run remotely against workstations with no Active Directory membership. Administrators commonly pair it with a remote execution method such as PsExec or WinRM to push the same INF template to a group of standalone machines. The other tools are interactive consoles limited to the local computer.

Why the other options are wrong

  • B. secpol.msc is a graphical console for editing local security policy on one machine and offers no scripting or deployment capability.
  • C. gpedit.msc edits Local Group Policy through a GUI on a single computer, so it cannot be scripted to deploy a policy across the network.

Question 3

A brewer uses a local HMI to communicate with a controller that opens a pump to move the wort from the boil kettle to the fermentor. What level of the Purdue model would the controller be considered?

  1. Level 2
  2. Level 1
  3. Level 0
  4. Level 3
  5. Level 4
Show answer and explanation

Correct answer: B. Level 1

In the Purdue model, Level 1 is basic control: the PLCs, RTUs and DCS controllers that read field signals and issue commands to the process. The controller driving the pump that moves wort from the boil kettle to the fermentor performs that basic control function, so it sits at Level 1. The local HMI talking to it belongs at Level 2, and the pump itself is the Level 0 field device.

Why the other options are wrong

  • A. Level 2 is area supervisory control, covering HMIs, SCADA servers and operator workstations rather than the controller itself.
  • C. Level 0 is the physical process and its field devices such as the pump, valves and sensors, not the logic controller commanding them.
  • D. Level 3 is site operations, including manufacturing execution systems, historians and production scheduling.
  • E. Level 4 is the enterprise business network with ERP and corporate IT systems.

See all 10 free questions Get the full pack, US$39

78 practice questions for GIAC Global Industrial Cyber Security Professional (GICSP) certification, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 78 questions mapped to the GICSP exam certification objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A GICSP attempt costs US$999 (US$899 for a retake). This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 78 questions

What makes the GICSP hard

GICSP is the GIAC certification paired with SANS ICS410, and it is written deliberately for the seam between IT security and control engineering: an IT security person will find the process control and safety material unfamiliar, and an engineer will find the network defence material unfamiliar.

It is 82 questions in three hours with a 71% pass mark, open book with hardcopy materials, and it is a CyberLive exam, so some questions are hands-on tasks in a virtual machine rather than multiple choice.

The objectives cover ten areas: ICS overview and how OT differs from IT, ICS architecture including the Purdue model and zones and conduits, field devices such as PLCs, RTUs and HMIs, industrial protocols such as Modbus, DNP3 and OPC, the ICS attack surface from Stuxnet onward, defending ICS servers and workstations, network security for ICS, governance and standards, and incident response and recovery in an environment where reimaging is not an option. The CyberLive tasks tend to be packet analysis or configuration review, so it is worth practising reading protocol captures.

About the exam

GICSP (GIAC Global Industrial Cyber Security Professional) validates the foundational knowledge needed to secure industrial control systems: ICS architecture and components, industrial protocols, the ICS attack surface, defending ICS hosts and networks, governance and standards, and incident response. There are no prerequisites; it is aligned to SANS ICS410.

Exam certification objectives

  • ICS overview and how OT differs from IT
  • ICS architecture, Purdue model, zones and conduits
  • Field devices, controllers, HMIs and historians
  • Industrial protocols and their weaknesses
  • ICS attack surface and threat landscape
  • Defending ICS servers, workstations and applications
  • ICS network security and monitoring
  • Governance, risk, standards and policy
  • Incident response and recovery for ICS

GIAC does not publish weightings. 82 questions including CyberLive hands-on tasks, 180 minutes, open book (hardcopy only), passing score 71%, US$999 per attempt, ProctorU remote or Pearson VUE test centre, certification valid for four years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Global Industrial Cyber Security Professional GICSP pack?

78 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.