Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the GIAC Cyber Security GICSP Questions and answers with ValidTests

Exam GICSP All Questions
Exam GICSP Premium Access

View all detail and faqs for the GICSP exam

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which of the following is typically performed during the Recovery phase of incident response?

Options:

A.

Updating the organization's security policies to prevent future breaches.

B.

Patching and configuring systems to meet established secure configuration standards.

C.

Finding the root cause or vector used by the attacker to gain entry and maintain access.

D.

Making a forensic image of the system(s) involved in the incident.

Expert Solution
Questions # 22:

An attacker crafts an email that will send a user to the following site if they click a link in the message. What else is necessary for this type of attack to work?

Question # 22

Options:

A.

The attacker must obtain a session cookie from an authorized HMI user

B.

The user clicking the link must be an administrator on the network

C.

The user must be authenticated to the HMI interface before clicking the link

D.

The attacker must enclose the URL parameter with <script> tags to run the code

Expert Solution
Questions # 23:

Which of the following is a facilitated tabletop exercise that is run in odd years and provides an overall public Lessons Learned report each year it is run?

Options:

A.

CRPA

B.

E-ISAC

C.

GridEx

D.

CTEP

Expert Solution
Questions # 24:

What is an output of a Business Impact Analysis?

Options:

A.

Determining the maximum time that systems can be offline

B.

Prioritizing the business's processes

C.

Calculating the financial impact of a technology failure

D.

Understanding all of the business's technology functions

Expert Solution
Questions # 25:

In the context of ICS the process of fuzzing a device is described as which of the following?

Options:

A.

Brute force password attacks against default accounts

B.

Launching all known exploits at the device in a randomized sequence

C.

Providing invalid, unexpected, or random data as inputs

D.

Monitoring device performance in varying power conditions

E.

Monitoring device performance in harsh environmental conditions

Expert Solution
Questions # 26:

A brewer uses a local HMI to communicate with a controller that opens a pump to move the workfrom the boil kettle to the fermentor. What level of the Purdue model would the controller be considered?

Options:

A.

Level 2

B.

Level 1

C.

Level 0

D.

Level 3

E.

Level 4

Expert Solution
Questions # 27:

At which offset of ~/GIAC/memdump/raw/key_13does binwalkindicate is the beginning of the binary file?

Options:

A.

0x2712

B.

0x33c1

C.

0x3400

D.

0x08el

E.

0x5df0

F.

0x5b66

G.

0x0000

Expert Solution
Questions # 28:

An organization has their ICS operations and networking equipment installed in the Purdue model level 3. Where should the SIEM for this equipment be placed in relation to the existing Level 3 devices?

Options:

A.

On a different subnet in Level 3

B.

On a management subnet in Level 4

C.

On a management subnet in Level 2

D.

On the same subnet in Level 3

Expert Solution
Questions # 29:

According to the DHS suggested patch decision tree, what should the next step be if there is a vulnerability with an available patch, but without an available workaround?

Options:

A.

Determine if the vulnerability affects the ICS

B.

Determine if the operational needs are greater than the risk

C.

Test and apply the patch

D.

Identify the vulnerability and the available patch

Expert Solution
Questions # 30:

Which of the following would use round-robin process scheduling?

Options:

A.

Embedded device on the plant floor

B.

Temperature sensor in the field

C.

Operator workstation in the control room

D.

Data-diode at an enforcement boundary

Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions