All questions

NERC Critical Infrastructure Protection (CIP) Practice Exam

Browse all practice questions for the NERC Critical Infrastructure Protection (CIP) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Conquer the 2026 NERC CIP Challenge – Secure Success and Energize Your Future! course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is an advantage of using VLANs in a network?
  • The NERC Reliability Functional Model is designed to ensure the reliability of what type of system?
  • How does the Bottom Up approach function in BES Cyber Asset identification?
  • What is the primary focus of CIP-014?
  • Which of the following describes a proxy server's filtering capability?
  • What is the primary goal of Security Information Event Management (SIEM) in relation to utility reliability?
  • How does security event management relate to Cyber Assets?
  • What do BES Reliability Operating Services (BROS) contribute to?
  • What is one critical component of a mitigation plan for deferred security patches?
  • What role do antivirus servers play in security architecture?
  • What should be included in Periodic Reviews of BES Cyber Assets?
  • In a firewall redundancy strategy, what defines a hot backup?
  • What is the recommended practice to mitigate threats on removable media?
  • What is the purpose of a 'heartbeat' in firewall configurations?
  • What distinguishes standard ACLs from extended ACLs in networking?
  • What did FERC Letter Order approve regarding Reliability Standard CIP-003-8?
  • Which architecture aspect is crucial for Security Information Event Management (SIEM)?
  • What is a key benefit of utilizing a staged rollout strategy for signature updates?
  • Which of the following best describes VLANs?
  • Which entity primarily works through audits, self-reports, and enforcement?
  • Which firewall type uses deep packet inspection to analyze content?
  • What should be documented after conducting a vulnerability assessment?
  • Which type of filtering requires knowledge of both inbound and outbound network traffic?
  • What characteristic defines the vulnerability of stateless packet filtering firewalls?
  • Why is timely patching critical for stateful inspection firewalls?
  • What does CIP-007 R4 require regarding event logging?
  • What is the main advantage of using proxies as firewalls?
  • What is a significant disadvantage of using VLANs?
  • What type of access control list is typically associated with routers?
  • Which of the following is true about physical I/O ports?
  • What must be done before performing a full active pen test at transmission substations?
  • What does the term "transient cyber assets" refer to in the context of CIP?
  • What must be retained for 90 days as per physical access requirements?
  • What is one of the steps in Configuration Change Management under CIP-010 R1?
  • FERC Order 791 is primarily concerned with the changes resulting in which version of the CIP Standards?
  • What advantage does an IPS provide compared to an IDS?
  • What is a requirement for Interactive Remote Access sessions according to CIP-005 R2?
  • Which of the following is a characteristic of an active vulnerability assessment?
  • What is one key consideration when applying patches?
  • Which of the following must be included in a documented plan for securing Real-Time Communication?
  • Which types of external communications are exempt according to CIP-002 5.1?
  • What should be done with the evidence collected for physical I/O ports?
  • What command is used by auditors to identify open ports?
  • What evidence should be documented to support the physical and logical port management process?
  • What must be documented within 90 days after testing a Cyber Security Incident response plan?
  • What is a potential limitation of using a proxy firewall?
  • Which order focuses on mitigating risk associated with malicious code on third-party Transient Cyber Assets?
  • What is mandated by CIP-004 R1 regarding security awareness?
  • According to CIP-006 R2, what is required for visitor access in physical security?
  • What should be monitored within 15 minutes according to the monitoring requirements?
  • What is a disadvantage of stateless packet filtering firewalls?
  • What should occur every 36 months when it pertains to active vulnerability assessments?
  • Which describes a benefit of application whitelisting?
  • What is a condition under which the physical security plan of a transmission facility may require third-party review?
  • What is a primary risk associated with the use of an IPS?
  • What does the recovery plan ensure regarding data preservation?
  • What does Functional Registration require from entities?
  • What distinguishes a scan of interest from a sequential port scan?
  • What is a requirement for having electronic routable communications in a network?
  • What type of maintenance is required for Physical Access Control Systems according to CIP-006 R3?
  • What should happen within 30 calendar days for deviations from the baseline configuration?
  • What must be done to known default passwords according to CIP-007 R5?
  • What is a primary characteristic of ICS-specific firewalls?
  • What is the initial notification timeframe for Reportable Cyber Security Incidents?
  • What was the main reason for the establishment of NERC?
  • What should be enabled on USB devices to enhance security?
  • What type of logging is required for visitors according to the visitor control program?
  • When was NERC formed as a non-profit organization?
  • When applying security to a BES Cyber Asset, which approach should be prioritized?
  • How often should logged events be reviewed, according to security event monitoring standards?
  • What should be done with the outputs from running configuration reviews?
  • Which document is essential for timely evaluation and implementation of security patches?
  • What does the term "ephemeral port" refer to?
  • Which entities must be notified of Reportable Cyber Security Incidents?
  • What is a potential risk when using stateless packet filtering firewalls?
  • Which statement best describes the nature of a vulnerability assessment?
  • What is one of the conditions for activating the recovery plan?
  • What is the primary purpose of the Buddy System Model for grouping assets?
  • Which organization is associated with the Purdue Model of network architecture?
  • What type of audits are commonly referred to as 706 audits?
  • According to NERC CIP, which assets must comply if they operate certain types of load shedding equipment?
  • What is the range of Well-Known ports as defined by IANA?
  • What is a key requirement of System Access Control under CIP-007 R5?
  • How is "implementation" of supply chain cybersecurity plans demonstrated?
  • What is one of the main actions following the detection of malicious code in a system?
  • What does the acronym FERC stand for?
  • What type of firewalls serves as a redundancy strategy in network security?
  • What is the required frequency for conducting vulnerability assessments as outlined in CIP-010 R3?
  • Which organization is responsible for implementing NERC's standards and procedures?
  • Which type of firewall operates based solely on source and destination information?
  • Which process is critical for managing post-approval changes to the authorization scope?
  • Which of the following actions is recommended after implementing changes to baseline configurations?
  • What is the purpose of identifying UFLS and UVLS systems as part of the Distribution Provider Applicable facilities?
  • How frequently should security patches be evaluated?
  • What is the purpose of the NERC Reliability Functional Model?
  • How does a Network IDS (NIDS) primarily monitor communications?
  • What is required before adding a new applicable Cyber Asset to a production environment?
  • What must any future procurement contracts address regarding vendors?
  • What potential issue can arise from signature updates in IDS systems?
  • Which of the following areas is NOT a required topic in Cyber Security policies?
  • What makes an Intrusion Prevention System (IPS) different from an IDS?
  • What capability does application deep packet inspection firewalls include?
  • How does FERC Order 822 relate to inter-control center communications?
  • What was a significant requirement introduced by FERC Order 822?
  • Which group is specifically mentioned as needing access through Interactive Remote Access?
  • What is a required action to prevent malicious code according to CIP-007 R3?
  • What is a key requirement for device-level protection of logical ports?
  • What aspect of the electric transmission system does the Energy Policy Act of 2005 focus on?
  • Which attack is associated with VLAN exploits?
  • Which firewall type is primarily used to filter web traffic?
  • How frequently must Cyber Security Incident response plans be tested?
  • What is one of the goals of conducting vulnerability assessments?
  • What is a feature of an intrusion detection system in relation to host activity?
  • What is an appropriate local internal action in response to detected malicious code?
  • What is a logical protection method for securing cables and nonprogrammable communication?
  • How are BES Cyber Assets logically grouped into BES Cyber Systems?
  • What is one method to control physical ports effectively?
  • Which tool does the audit team utilize to select random samples from data populations?
  • Which of the following describes a technical control for physical ports?
  • Which assets are exempt from NERC CIP regulations as per the applicability exemptions?
  • How often should the CIP Senior Manager review and approve plans?
  • How often must recovery plans be tested?
  • Which is a goal of the BES Cyber Asset identification process?
  • What entities are sources for obtaining patches?
  • Which order is associated with the approval of CIP audits, often referred to as 706 audits?
  • How do CIP-010 and CIP-007 interconnect regarding patch management?
  • What should be included in a security patch management process?
  • What are the primary components of the Four Legged Firewall?
  • What is the first step in the security patching process according to NERC CIP standards?
  • The Texas Reliability Entity (TRE) is one of how many regional entities?
  • What is a significant issue related to application whitelisting after periodic updates?
  • What is vital to consider in your patch management universe according to CIP-010?
  • How many Regional Entities are there under NERC?
  • What is a unique feature of data diodes in perimeter defense?
  • What is the primary function of assets in the security patching architecture?
  • Which of the following is not one of the NERC Regional Entities?
  • What should the physical security plan include according to CIP-006 R1?
  • Which of the following topics should be covered in a Cyber Security training program?
  • Which professional designation is specifically focused on physical security?
  • What is the primary goal of applying requirements to specific Cyber Assets?
  • How should unauthorized changes to the baseline configuration be handled?
  • Which section must be included in the documented plans for Transient Cyber Assets?
  • What distinguishes assets from systems in terms of security management?
  • What does a stateful inspection firewall do that a stateless packet filtering firewall does not?
  • Which FERC Order approved the CIP Version 3 set of Standards?
  • How frequently should security event logs be reviewed to identify undetected cyber security incidents?
  • Which event is used to demonstrate compliance configuration-related actions?
  • What should the review of BES Cyber Asset identification include in terms of categorization?
  • What is part of the documentation needed for the procurement plan?
  • What is a primary advantage of dial-up access control?
  • What should an organization do when a critical asset goes End of Life (EOL)?
  • What is crucial to document and notify according to cyber security risk management plans?
  • What should be updated within 60 calendar days after a change in roles or responsibilities?
  • What is a key consideration in the BES Cyber Asset identification process?
  • How are logical ports categorized according to their usage by the IANA?
  • What is a major characteristic of the patching timeline?
  • What aspect of ICS-specific firewalls allows for tailored security measures?
  • What is the default recovery period after the start of a reportable disturbance in BES Cyber Assets?
  • Which of the following is an advantage of stateful inspection firewalls?
  • What does FERC Order 693 primarily approve?
  • Cyber threats to ICS environments include which of the following types of activities?
  • What was a driving factor behind the increase in ICS-focused cyber attacks?
  • What is necessary for USB device safety according to the outlined protections?
  • Who is responsible for classifying a Reportable Cyber Security Incident?
  • What standard previously focused on sabotage reporting requirements before being retired?
  • Which office of FERC is focused on electric reliability?
  • What is a common disadvantage of Intrusion Detection Systems (IDS)?
  • What is a key focus of FERC Order 843?
  • In which layer of the OSI model do stateless packet filtering firewalls operate?
  • What can be considered a successful security patch management practice?
  • What is the role of an Intrusion Detection System (IDS)?
  • How often must CIP senior managers approve Cyber Security policies?
  • Where should directory servers used for authentication be located according to security guidelines?
  • What is a potential disadvantage of using dial-up connectivity?
  • What facilities are categorized under CIP-002 BES Cyber System Categorization?
  • What does vulnerability management focus on?
  • What system architecture can be utilized to limit dial-up connections?
  • How often should the identification of BES Cyber Assets be reviewed or updated?
  • How often should configuration monitoring take place for high impact BES systems according to CIP-010?
  • What is the significance of the 1500 MW generation threshold in BES Cyber Systems?
  • What is an example of a facility type included in the bulk-power system under the Energy Policy Act of 2005?
  • What clarification did FERC Order 706-B provide?
  • Which of the following is required for the physical access control system according to CIP-006 R3?
  • What does a unidirectional gateway combine to ensure information transfer in one direction?
  • What is required for signature updates in compliance with CIP-005?
  • Why is it important to perform regular reviews of dial-up logging capabilities?
  • Which type of facilities does CIP-014 apply to?
  • When updating the recovery plan, which document should be reviewed?
  • What is the recommended action regarding unneeded protocols in Windows configurations?
  • In the standards development process, what is the first step listed in the Standards Authorization Request form (SAR)?
  • In Linux, what should be done with unnecessary operational packages?
  • Who is responsible for approving the list of identified BES Cyber Assets?
  • What is required of an unaffiliated third party in relation to risk assessments?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy