ICS456 “50 Most Likely Exam Questions” Cheat
Sheet
NERC CIP Critical Infrastructure Protection
1.
Which standard defines BES Cyber System categorization?
A. CIP-002
B. CIP-007
C. CIP-010
D. CIP-011
Answer: A
Rationale:
CIP-002 establishes the process for identifying and categorizing BES Cyber Systems.
2.
Which standard governs security management controls?
A. CIP-003
B. CIP-006
C. CIP-007
D. CIP-013
Answer: A
Rationale:
CIP-003 requires policies, governance, and accountability for cybersecurity management.
3.
Which CIP standard covers personnel risk assessments and training?
A. CIP-004
B. CIP-005
,C. CIP-007
D. CIP-010
Answer: A
Rationale:
CIP-004 ensures individuals with cyber access undergo background screening and security
training.
4.
Which standard establishes Electronic Security Perimeter protections?
A. CIP-005
B. CIP-006
C. CIP-007
D. CIP-008
Answer: A
Rationale:
CIP-005 protects network boundaries around BES Cyber Systems.
5.
Which CIP standard addresses physical security of BES Cyber Systems?
A. CIP-006
B. CIP-007
C. CIP-008
D. CIP-009
Answer: A
Rationale:
CIP-006 requires physical access controls and monitoring for facilities housing critical
systems.
6.
, Which standard governs system security management?
A. CIP-007
B. CIP-009
C. CIP-010
D. CIP-013
Answer: A
Rationale:
CIP-007 includes patch management, port management, and security event monitoring.
7.
Which CIP standard requires incident reporting and response plans?
A. CIP-008
B. CIP-006
C. CIP-010
D. CIP-011
Answer: A
Rationale:
CIP-008 defines requirements for cybersecurity incident response and reporting.
8.
Which standard governs recovery plans for BES Cyber Systems?
A. CIP-009
B. CIP-007
C. CIP-010
D. CIP-013
Answer: A
Rationale:
CIP-009 ensures systems can recover after cyber incidents.
Sheet
NERC CIP Critical Infrastructure Protection
1.
Which standard defines BES Cyber System categorization?
A. CIP-002
B. CIP-007
C. CIP-010
D. CIP-011
Answer: A
Rationale:
CIP-002 establishes the process for identifying and categorizing BES Cyber Systems.
2.
Which standard governs security management controls?
A. CIP-003
B. CIP-006
C. CIP-007
D. CIP-013
Answer: A
Rationale:
CIP-003 requires policies, governance, and accountability for cybersecurity management.
3.
Which CIP standard covers personnel risk assessments and training?
A. CIP-004
B. CIP-005
,C. CIP-007
D. CIP-010
Answer: A
Rationale:
CIP-004 ensures individuals with cyber access undergo background screening and security
training.
4.
Which standard establishes Electronic Security Perimeter protections?
A. CIP-005
B. CIP-006
C. CIP-007
D. CIP-008
Answer: A
Rationale:
CIP-005 protects network boundaries around BES Cyber Systems.
5.
Which CIP standard addresses physical security of BES Cyber Systems?
A. CIP-006
B. CIP-007
C. CIP-008
D. CIP-009
Answer: A
Rationale:
CIP-006 requires physical access controls and monitoring for facilities housing critical
systems.
6.
, Which standard governs system security management?
A. CIP-007
B. CIP-009
C. CIP-010
D. CIP-013
Answer: A
Rationale:
CIP-007 includes patch management, port management, and security event monitoring.
7.
Which CIP standard requires incident reporting and response plans?
A. CIP-008
B. CIP-006
C. CIP-010
D. CIP-011
Answer: A
Rationale:
CIP-008 defines requirements for cybersecurity incident response and reporting.
8.
Which standard governs recovery plans for BES Cyber Systems?
A. CIP-009
B. CIP-007
C. CIP-010
D. CIP-013
Answer: A
Rationale:
CIP-009 ensures systems can recover after cyber incidents.