SC CRITICAL INFRASTRUCTURE PROTECTION CERTIFICATION EXAM – QUESTIONS AND ANSWERS | VERIFIED
AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE
Core Domains:
1. Critical Infrastructure Identification and Prioritization
2. Risk Management and Vulnerability Assessment
3. Physical Security Measures and Controls
4. Cybersecurity Principles for Industrial Control Systems (ICS) and SCADA
5. Regulatory Compliance and Legal Frameworks (e.g., NIST, CISA, PPD-21)
6. Emergency Response and Business Continuity Planning
7. Insider Threat Detection and Mitigation
8. Interdependencies and Sector-Specific Risks
9. Security Governance and Ethical Standards
10. Intelligence Gathering and Threat Analysis
Introduction
This comprehensive examination is designed to rigorously assess a candidate's knowledge and practical proficiency in
the principles and practices of critical infrastructure protection. The exam delves into core competencies, including risk
identification, security architecture, and crisis management, across both physical and cyber domains. Candidates will be
evaluated on their ability to apply foundational theory, navigate complex regulatory and legal landscapes, and uphold
professional ethical standards. Through a combination of multiple-choice and scenario-based questions, this
assessment emphasizes real-world application and decision-making, preparing professionals to effectively identify,
deter, and mitigate threats to a nation's essential assets and systems.
,Section One: Questions 1–100
1. The primary goal of the National Infrastructure Protection Plan (NIPP) is to:
A. Provide financial assistance to private sector owners.
B. Develop a framework for a single, unified national security strategy.
C. Manage and reduce risk to critical infrastructure by securing against all hazards.
D. Centralize all critical infrastructure data under a single federal agency.
🟢C
🔴 Explanation: The NIPP outlines the national approach to critical infrastructure security and resilience, focusing on
managing and reducing risk from all hazards (physical, cyber, and natural) through public-private partnerships. It
does not create a single strategy or agency but provides a framework for collaborative action.
2. Which of the following is the BEST example of an interdependency between the Energy and Water sectors?
A. Water is used for cooling in power plants.
B. Energy is required to power SCADA systems for water treatment.
C. Both sectors rely on the telecommunications sector for data.
D. Both sectors require highly skilled cybersecurity personnel.
🟢A
🔴 Explanation: This illustrates a physical interdependency where the Energy sector relies on the Water sector as an
input for its core operations. Option B highlights a dependency of Water on Energy, which is also a valid
interdependency but typically framed as Energy's reliance on Water for cooling. The question asks for the "best"
example, and the direct physical input is a classic example.
,3. Within the context of ICS security, what is the primary function of a "Defense-in-Depth" strategy?
A. To create multiple layers of protection to ensure no single point of failure compromises the system.
B. To install the most advanced firewall available at the network perimeter.
C. To focus security efforts solely on the Human-Machine Interface (HMI).
D. To eliminate all external network connections to the control system.
🟢A
🔴 Explanation: Defense-in-depth is a layered security approach that uses multiple, overlapping protective
measures. If one layer is breached, subsequent layers are in place to stop the threat. It is not a single solution (like a
firewall) or limited to one component.
4. The PPD-21 (Presidential Policy Directive 21) identifies 16 critical infrastructure sectors. Which of the following
is NOT one of these sectors?
A. Healthcare and Public Health
B. Information Technology
C. Retail and Consumer Goods
D. Chemical
🟢C
🔴 Explanation: PPD-21 designates 16 critical infrastructure sectors, which include Healthcare and Public Health,
Information Technology, and Chemical. Retail and Consumer Goods is not one of the designated sectors.
5. An incident response team is executing a disaster recovery plan after a ransomware attack has encrypted key
servers. What is the MOST critical step to perform BEFORE initiating data restoration from backups?
A. Verify the integrity and security of the backups.
B. Isolate the affected network segment.
, C. Notify law enforcement.
D. Determine the ransomware variant.
🟢A
🔴 Explanation: The first priority in recovery is to ensure the backups themselves are not compromised. Restoring
from a corrupted or infected backup would re-introduce the problem. While isolating the network is crucial, it
should have been the first step in containment; verification of backups is the critical step before restoration.
6. A vulnerability assessment has revealed that a water treatment facility's control system is using default
credentials. Which risk management strategy is MOST appropriate as an immediate corrective action?
A. Risk Acceptance
B. Risk Mitigation
C. Risk Transference
D. Risk Avoidance
🟢B
🔴 Explanation: Risk mitigation involves taking action to reduce the likelihood or impact of a risk. Changing default
credentials directly reduces the vulnerability, thus mitigating the risk. Acceptance would be inappropriate,
transference (e.g., insurance) doesn't fix the problem, and avoidance (shutting down the system) is not a practical or
appropriate immediate action.
7. Which regulatory framework is most directly applicable to the security of Bulk Electric System (BES) cyber
assets in North America?
A. HIPAA (Health Insurance Portability and Accountability Act)
B. FISMA (Federal Information Security Modernization Act)
AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE
Core Domains:
1. Critical Infrastructure Identification and Prioritization
2. Risk Management and Vulnerability Assessment
3. Physical Security Measures and Controls
4. Cybersecurity Principles for Industrial Control Systems (ICS) and SCADA
5. Regulatory Compliance and Legal Frameworks (e.g., NIST, CISA, PPD-21)
6. Emergency Response and Business Continuity Planning
7. Insider Threat Detection and Mitigation
8. Interdependencies and Sector-Specific Risks
9. Security Governance and Ethical Standards
10. Intelligence Gathering and Threat Analysis
Introduction
This comprehensive examination is designed to rigorously assess a candidate's knowledge and practical proficiency in
the principles and practices of critical infrastructure protection. The exam delves into core competencies, including risk
identification, security architecture, and crisis management, across both physical and cyber domains. Candidates will be
evaluated on their ability to apply foundational theory, navigate complex regulatory and legal landscapes, and uphold
professional ethical standards. Through a combination of multiple-choice and scenario-based questions, this
assessment emphasizes real-world application and decision-making, preparing professionals to effectively identify,
deter, and mitigate threats to a nation's essential assets and systems.
,Section One: Questions 1–100
1. The primary goal of the National Infrastructure Protection Plan (NIPP) is to:
A. Provide financial assistance to private sector owners.
B. Develop a framework for a single, unified national security strategy.
C. Manage and reduce risk to critical infrastructure by securing against all hazards.
D. Centralize all critical infrastructure data under a single federal agency.
🟢C
🔴 Explanation: The NIPP outlines the national approach to critical infrastructure security and resilience, focusing on
managing and reducing risk from all hazards (physical, cyber, and natural) through public-private partnerships. It
does not create a single strategy or agency but provides a framework for collaborative action.
2. Which of the following is the BEST example of an interdependency between the Energy and Water sectors?
A. Water is used for cooling in power plants.
B. Energy is required to power SCADA systems for water treatment.
C. Both sectors rely on the telecommunications sector for data.
D. Both sectors require highly skilled cybersecurity personnel.
🟢A
🔴 Explanation: This illustrates a physical interdependency where the Energy sector relies on the Water sector as an
input for its core operations. Option B highlights a dependency of Water on Energy, which is also a valid
interdependency but typically framed as Energy's reliance on Water for cooling. The question asks for the "best"
example, and the direct physical input is a classic example.
,3. Within the context of ICS security, what is the primary function of a "Defense-in-Depth" strategy?
A. To create multiple layers of protection to ensure no single point of failure compromises the system.
B. To install the most advanced firewall available at the network perimeter.
C. To focus security efforts solely on the Human-Machine Interface (HMI).
D. To eliminate all external network connections to the control system.
🟢A
🔴 Explanation: Defense-in-depth is a layered security approach that uses multiple, overlapping protective
measures. If one layer is breached, subsequent layers are in place to stop the threat. It is not a single solution (like a
firewall) or limited to one component.
4. The PPD-21 (Presidential Policy Directive 21) identifies 16 critical infrastructure sectors. Which of the following
is NOT one of these sectors?
A. Healthcare and Public Health
B. Information Technology
C. Retail and Consumer Goods
D. Chemical
🟢C
🔴 Explanation: PPD-21 designates 16 critical infrastructure sectors, which include Healthcare and Public Health,
Information Technology, and Chemical. Retail and Consumer Goods is not one of the designated sectors.
5. An incident response team is executing a disaster recovery plan after a ransomware attack has encrypted key
servers. What is the MOST critical step to perform BEFORE initiating data restoration from backups?
A. Verify the integrity and security of the backups.
B. Isolate the affected network segment.
, C. Notify law enforcement.
D. Determine the ransomware variant.
🟢A
🔴 Explanation: The first priority in recovery is to ensure the backups themselves are not compromised. Restoring
from a corrupted or infected backup would re-introduce the problem. While isolating the network is crucial, it
should have been the first step in containment; verification of backups is the critical step before restoration.
6. A vulnerability assessment has revealed that a water treatment facility's control system is using default
credentials. Which risk management strategy is MOST appropriate as an immediate corrective action?
A. Risk Acceptance
B. Risk Mitigation
C. Risk Transference
D. Risk Avoidance
🟢B
🔴 Explanation: Risk mitigation involves taking action to reduce the likelihood or impact of a risk. Changing default
credentials directly reduces the vulnerability, thus mitigating the risk. Acceptance would be inappropriate,
transference (e.g., insurance) doesn't fix the problem, and avoidance (shutting down the system) is not a practical or
appropriate immediate action.
7. Which regulatory framework is most directly applicable to the security of Bulk Electric System (BES) cyber
assets in North America?
A. HIPAA (Health Insurance Portability and Accountability Act)
B. FISMA (Federal Information Security Modernization Act)