(GICSP) Practice Exam 2026 Edition
Q1. Which characteristic best differentiates Industrial Control Systems (ICS) from traditional IT
systems?
A. Frequent system updates
B. Emphasis on confidentiality
C. Deterministic real-time operation
D. Use of cloud-based services
Correct Answer: C
Explanation:
ICS prioritize deterministic and real-time performance to ensure predictable and safe physical
process control, unlike IT systems that focus more on data processing and confidentiality.
Q2. Which of the following is a primary objective of ICS cybersecurity?
A. Maximizing data throughput
B. Ensuring safety and availability
C. Increasing software portability
D. Reducing hardware redundancy
Correct Answer: B
Explanation:
ICS cybersecurity focuses on safety, availability, and reliability of physical processes, often
outweighing confidentiality concerns.
Q3. Which system is responsible for supervisory control and data acquisition?
A. PLC
B. RTU
C. SCADA
D. DCS
Correct Answer: C
Explanation:
SCADA systems provide centralized supervisory control, monitoring remote field devices via RTUs or
PLCs.
Q4. Which protocol is commonly used for industrial automation and is inherently insecure by
design?
A. HTTPS
B. Modbus TCP
, Global Industrial Cyber Security Professional
(GICSP) Practice Exam 2026 Edition
C. SFTP
D. IPsec
Correct Answer: B
Explanation:
Modbus TCP lacks authentication and encryption, making it insecure by default, a common issue
with legacy ICS protocols.
Q5. What is the primary function of a Programmable Logic Controller (PLC)?
A. Data analytics
B. Human-machine interaction
C. Real-time control of processes
D. Network routing
Correct Answer: C
Explanation:
PLCs execute real-time control logic to operate machinery and industrial processes.
Q6. Which network model is recommended for segmenting ICS environments?
A. Flat network model
B. Purdue Enterprise Reference Architecture
C. Peer-to-peer model
D. Client-server model
Correct Answer: B
Explanation:
The Purdue Model defines hierarchical levels and segmentation to improve security and control in
ICS networks.
Q7. What is the primary risk of applying IT-style patching practices directly to ICS systems?
A. Increased compliance
B. Reduced encryption
C. System instability or downtime
D. Faster recovery
Correct Answer: C
Explanation:
ICS systems require carefully tested patches, as improper updates may disrupt real-time operations
or safety.
, Global Industrial Cyber Security Professional
(GICSP) Practice Exam 2026 Edition
Q8. Which ICS layer typically contains PLCs and RTUs in the Purdue Model?
A. Level 0
B. Level 1
C. Level 2
D. Level 4
Correct Answer: B
Explanation:
Level 1 includes basic control devices such as PLCs and RTUs that interact with field devices.
Q9. Which security principle is most critical for ICS environments?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Correct Answer: C
Explanation:
Loss of availability in ICS can cause production outages or safety incidents, making it the top priority.
Q10. What is an HMI primarily used for?
A. Network monitoring
B. Operator visualization and control
C. Firmware updates
D. Authentication services
Correct Answer: B
Explanation:
HMIs provide operators with visual insight and control over industrial processes.
Q11. Which organization publishes the IEC 62443 standards?
A. ISO
B. IEEE
C. IEC
D. NIST
Correct Answer: C
Explanation:
The International Electrotechnical Commission (IEC) develops IEC 62443 for ICS cybersecurity.
, Global Industrial Cyber Security Professional
(GICSP) Practice Exam 2026 Edition
Q12. Which threat actor is most likely to target critical infrastructure ICS?
A. Script kiddies
B. Hacktivists
C. Nation-state actors
D. Insider threat only
Correct Answer: C
Explanation:
Nation-state actors often target ICS for geopolitical, espionage, or sabotage purposes.
Q13. What is the primary function of a safety instrumented system (SIS)?
A. Process optimization
B. Network security
C. Prevent hazardous events
D. Data storage
Correct Answer: C
Explanation:
SIS systems are designed to maintain safe operating conditions and prevent catastrophic failures.
Q14. Which component separates the enterprise network from the control network?
A. PLC
B. Firewall
C. HMI
D. RTU
Correct Answer: B
Explanation:
Firewalls enforce network segmentation and access control between IT and OT networks.
Q15. Which protocol is commonly used for time synchronization in ICS networks?
A. FTP
B. SNMP
C. NTP
D. SMTP
Correct Answer: C
Explanation:
Network Time Protocol (NTP) ensures consistent timestamps for logs and events.