GIAC GCIP Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Critical Infrastructure Protection (GCIP) |
| Exam Number: | GCIP |
| Related Certifications: | GIAC Secure Software Programmer (GSSP) GIAC Industrial Control Systems Security (GICSP) GIAC Information Security Professional (GISP) |
| Certificate Validity Period: | 4 years |
| Exam Format: | Open-book, open-notes, Multiple choice, Proctored |
| Real Exam Qty: | 75 |
| Exam Duration: | 180 minutes |
| Available Languages: | English |
| Exam Price: | $999 USD |
| Passing Score: | 70% |
| Recommended Training: | SANS ICS456: Essentials for NERC Critical Infrastructure Protection |
| Exam Registration: | GIAC Official Registration Pearson VUE Scheduling |
| Sample Questions: | GIAC GCIP Sample Questions |
| Exam Way: | Online remote proctoring (ProctorU) or Onsite proctoring (Pearson VUE) |
| Pre Condition: | Recommended: 2+ years of experience in critical infrastructure, NERC CIP compliance, or industrial control systems; completion of SANS ICS456 training |
| Official Syllabus URL: | https://www.giac.org/certifications/critical-infrastructure-protection-gcip |
GIAC GCIP Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Security Management Controls | 7% | |
| Topic 2: Physical Security of BES Cyber Systems | 7% | |
| Topic 3: Recovery Plans for BES Cyber Systems | 6% | |
| Topic 4: BES Cyber System Categorization | 10% | - Operational Effects and Impacts - Attachment 1 Criteria - BES Cyber Asset Identification |
| Topic 5: Configuration Change Management and Vulnerability Assessments | 8% | |
| Topic 6: Standards Development | 6% | |
| Topic 7: System Security Management | 10% | - Port and Service Management - Authentication and Access Control - Patch Management |
| Topic 8: Information Protection | 7% | |
| Topic 9: Incident Reporting and Response Planning | 8% | |
| Topic 10: Electronic Security Perimeter(s) | 9% | |
| Topic 11: Personnel & Training | 8% | |
| Topic 12: NERC CIP Terms and Definitions | 8% | |
| Topic 13: Standards Enforcement | 6% |
GIAC Critical Infrastructure Protection Sample Questions:
Question 1
How does continuous monitoring contribute to system security management?
Response:
A. It reduces system performance issues
B. It facilitates better communication among staff
C. It allows for early detection of cybersecurity incidents
D. It improves team collaboration
Question 2
What is a key benefit of conducting regular vulnerability assessments on BES Cyber Systems?
Response:
A. Reducing the need for user training.
B. Facilitating faster system upgrades.
C. Identifying and addressing security gaps before they can be exploited.
D. Ensuring compliance with international trade regulations.
Question 3
Which two key objectives must be achieved by NERC CIP cybersecurity training programs?
Response:
A. Increasing employee satisfaction
B. Improving office decor
C. Ensuring personnel understand their security roles and responsibilities
D. Teaching personnel to recognize potential cybersecurity threats
Question 4
Which of the following methods is most effective for protecting BES-related information during disposal?
Response:
A. Shredding physical documents
B. Leaving the documents in public areas
C. Emailing sensitive data to external stakeholders
D. Reusing the information for future projects
Question 5
Why is it important to accurately categorize BES Cyber Systems?
Response:
A. To ensure appropriate protection levels are applied.
B. To streamline employee access.
C. To prioritize systems for maintenance.
D. To facilitate insurance claims.
Solutions:
| Question 1 Answer: C | Question 2 Answer: C | Question 3 Answer: C,D | Question 4 Answer: A | Question 5 Answer: A |


PDF Version Demo






We are confident about the products and aim to help you pass with ease. In case of failure, we will provide a no hassle full money back guarantee for the purchasing fee.
1047 Customer Reviews
Quality and ValueITbraindumps Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITbraindumps testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITbraindumps offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.