All questions

NERC Critical Infrastructure Protection (CIP) v7 Standards and Requirements Practice Test

Browse all practice questions for the NERC Critical Infrastructure Protection (CIP) v7 Standards and Requirements Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

NERC Critical Infrastructure Protection (CIP) v7 Standards and Requirements Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is required to be issued in response to unauthorized access detected in a Physical Security Perimeter?
  • What does CIP-004 R5.2 entail regarding unescorted physical access?
  • What is the primary requirement outlined in CIP-009 R1 regarding recovery plans?
  • CIP-009 R1.4 requires processes for what specific activity?
  • What is the maximum interval for conducting a paper or active vulnerability assessment?
  • What should be done with unnecessary physical input/output ports according to CIP-007 R1.2?
  • What must Responsible Entities do for Transient Cyber Assets managed by them?
  • What is the maximum time frame for notifying groups defined in the recovery plan upon changes according to R3.2?
  • What does CIP-011 R2 primarily focus on?
  • What is a key activity required in the Personnel Risk Assessment Program?
  • CIP-004 R5.1 specifies a process to remove access for what situation?
  • What is the focus of CIP-009 R1.3 concerning recovery plans?
  • Which type of control must be utilized to enhance physical access security as per CIP-006?
  • According to CIP-008 R1.2, what must be done when a Cyber Security Incident is identified?
  • When performing an active vulnerability assessment, what should be included in the documentation?
  • What process does CIP-009 R2 emphasize should occur at least once every 15 calendar months?
  • Documenting the differences in environments during testing should include descriptions of what?
  • What is the purpose of documenting the execution status of remediation action items?
  • What must be included in a Visitor Control Program as outlined by CIP-006?
  • What is one method to mitigate software vulnerabilities on Transient Cyber Assets?
  • What key action is outlined in CIP-008 R3.1 with respect to updates on Cyber Security Incident response plans?
  • What is a key requirement of any physical security plan according to CIP-006 R1?
  • What is the purpose of electronic access controls for low impact BES Cyber Systems?
  • Which of the following is an essential part of the information protection program?
  • CIP-004 R5.5 outlines a timeline for changing passwords after what type of action?
  • What is the primary goal of the Security Awareness Program under CIP-004?
  • What is the focus of the restrictions placed on access to cabling used for communication?
  • What must changes to the existing baseline configuration be?
  • What is required at least once each calendar quarter under CIP-004 R4.2?
  • What does R2.1 specifically require to evaluate the response plan effectively?
  • Which method assists in mitigating unauthorized use of Transient Cyber Assets?
  • Which of the following is NOT included in a personnel risk assessment?
  • What is the minimum length requirement for passwords according to CIP-007 R5.5?
  • What is the required action for visitor access during non-CIP Exceptional Circumstances?
  • Which requirement involves the management and control of network ports and services?
  • What should be implemented according to CIP-005 R1 for the Electronic Security Perimeter?
  • What should be done when cabling and components used for communications are located outside of a Physical Security Perimeter?
  • Prior to reusing Cyber Assets, what must be done regarding data on the storage media?
  • What does CIP-006 R3 require from Responsible Entities regarding physical access control?
  • What should personnel do if there is a communication failure detected in physical access systems?
  • What type of security access must be documented and approved according to CIP-003?
  • Which type of systems does Requirement R1.3 pertain to?
  • What is emphasized by the CIP standards for managing Cyber Assets?
  • How frequently must a Cyber Security Incident response plan be tested?
  • What is one of the types of events that must be logged for Cyber Security Incidents?
  • What should Responsible Entities do before connecting a Transient Cyber Asset managed by a 3rd party?
  • What must be updated after documenting lessons learned from a recovery plan test, as per Requirement R3.1?
  • What type of assessment is specifically included in CIP-010 R3?
  • What is required to be documented after verifying that cyber security controls are unaffected by a change?
  • What is the maximum interval for reviewing logged events?
  • Under CIP-007 R5.7, what should be done after a threshold of unsuccessful authentication attempts is reached?
  • CIP-008 R2 specifies requirements for what process?
  • What must be logged for individuals with authorized unescorted access into a Physical Security Perimeter?
  • CIP-007 R5.6 requires passwords to be changed at least once every how many months?
  • What is the requirement for interactive remote access sessions according to CIP-005?
  • Which mitigation method focuses on detecting threats from removable media?
  • Which aspect is specifically mentioned in CIP-004 for those with authorized access?
  • According to CIP-008 R2.3, what should be done with records related to Reportable Cyber Security Incidents?
  • What is the focus of Requirement R4 in relation to Transient Cyber Assets?
  • Which of the following is a critical component of the process for disposal of Cyber Assets?
  • What does CIP-008 R2 require regarding incident response plans?
  • What is a substitute for an operational exercise for testing recovery plans?
  • Which of the following is part of CIP-010 R1.1 regarding baseline configurations?
  • What key aspect is addressed in CIP-010-2 related to BES Cyber Systems?
  • Under CIP-004 R4.3, how often must user accounts be verified for correct access privileges?
  • What is required under CIP-005 R1.2 for External Routable Connectivity?
  • In the context of CIP-011, what does the term "applicable Cyber Assets" refer to?
  • For the effective training of personnel, what should the Cyber Security Training Program include?
  • Which of the following is NOT included in the assets considered for categorization under CIP-002 R1?
  • Which of the following best describes the intent of the Recovery Plan Implementation in CIP-009 R2?
  • How should a Responsible Entity approach the reuse of Cyber Assets according to CIP-011 R2.1?
  • Which requirement emphasizes the secure handling of BES Cyber System Information?
  • What is the primary purpose of CIP-007 R5.2?
  • What is the focus of CIP-008-5?
  • Which entity is responsible for approving the identifications required by Requirement R1?
  • What is the recommended first step for mitigating the threat of malicious code on Removable Media?
  • CIP-003 R2 applies to which entities specifically?
  • Which of the following requirements is associated with CIP-011 R2.2?
  • What is the intent of the maintenance and testing program in CIP-006 R3?
  • What primary document is referenced for tracking cybersecurity patches in CIP-007?
  • Which process is essential for methods that use signatures or patterns?
  • Before implementing changes in a production environment, what should entities do when feasible?
  • Which of the following is a requirement under the Interactive Remote Access Management guidelines?
  • Which procedure is NOT part of effective management of BES Cyber System Information?
  • CIP-009 R1 requires Responsible Entities to have what sort of documentation in place?
  • In cases where malicious code is detected, what action must be taken?
  • For how long must visitor logs be retained?
  • What is the focus of Requirement R1.1 in CIP-002?
  • What is not an acceptable method to mitigate software vulnerabilities according to CIP-010?
  • Which action is related to CIP-004 R5.1 during termination processes?
  • Authorization for Transient Cyber Assets must include what aspects?
  • According to CIP requirements, what should the approach to Cyber Security Incident records be?
  • Which of the following is NOT a required action for patch management?
  • Which part of CIP-007 focuses on the regular assessment of cybersecurity patches?
  • How often must configuration monitoring be performed according to Requirement R2?
  • What overarching theme do the security management controls under CIP-003-7 address?
  • For which type of systems is RM Malicious Code Mitigation particularly applicable?
  • What must a Cyber Security Incident response plan include?
  • Which of the following is a process required for verifying personnel risk assessments for contractors?
  • Which of the following is a critical aspect of CIP-008 R3?
  • What is a requirement under CIP-007 R5?
  • What does CIP-005 R1.4 require regarding Dial-up Connectivity?
  • How often must security patches be evaluated according to CIP-007 R2.2?
  • What does CIP-007 R4 require entities to implement?
  • Which of the following is a requirement of CIP-004 R4.1?
  • Which of the following is a responsibility of a 3rd party regarding software vulnerability mitigation?
  • How often must employees complete the specified training to maintain access authorization?
  • Under which requirement is the identification of medium impact BES Cyber Systems detailed?
  • What must be in place according to CIP-005 R1.5 for detecting malicious communications?
  • How must Responsible Entities approach removable media authorization?
  • In CIP-007, which requirement focuses on handling and preventing the spread of malicious software?
  • What must a Responsible Entity implement regarding access management?
  • What is required of each Responsible Entity in relation to designating a CIP Senior Manager?
  • Which of the following is included in the procedures for protecting BES Cyber System Information?
  • What is the requirement if a Responsible Entity delegates authority regarding specific actions?
  • What is the key purpose of CIP-004 R3.3?
  • What is the focus of CIP-011 R1.1?
  • What is a recommended practice for maintaining software security?
  • Which approach is used to mitigate the introduction of malicious code?
  • What is required according to CIP-009 R1.4 regarding backup processes?
  • Which approach is recommended by CIP-007 R5.7 to enhance password security?
  • What does CIP-005 R2.1 specify about Interactive Remote Access?
  • Which of the following is a necessary action for interactive remote access sessions as per CIP-005 R2.3?
  • What precondition is stated before adding a new applicable Cyber Asset to the production environment?
  • CIP-009 R1.1 focuses on what specific aspect of recovery plans?
  • How often must Responsible Entities reinforce cybersecurity practices?
  • Prior to the release of Cyber Assets for reuse, what must a Responsible Entity do according to CIP-011?
  • Which requirement outlines protective measures for ports and services?
  • How long must event logs be retained under CIP requirements?
  • Which requirement involves identifying individuals with access to shared accounts?
  • What is the purpose of identifying high impact BES Cyber Systems according to CIP-002 R1.1?
  • What is the intent of the process outlined in CIP-007 R4?
  • CIP-007 R5.4 mandates the changing of what type of passwords?
  • In the context of CIP-005, what is an Electronic Access Point (EAP)?
  • What is required by CIP-006 R1.2 to allow unescorted access?
  • What should happen if a Cyber Security Incident response plan needs updates?
  • How long does the Responsible Entity have to implement a mitigation plan after its creation or revision?
  • According to CIP-005 R1.3, what is required for access permissions?
  • According to CIP-006 R1, what must each Responsible Entity implement?
  • What should be documented if a complete seven year criminal history records check cannot be performed?
  • According to CIP-009 R1.5, what is essential for preserving data during a recovery operation?
  • According to CIP-006 R1.1, what should be established to restrict physical access?
  • For how long must physical access logs be retained?
  • What does CIP Exceptional Circumstances refer to?
  • Which requirement emphasizes the documentation aspect of Cyber Security Incident response plans?
  • What does CIP-004 R4.4 focus on verifying?
  • What must occur if unauthorized physical access is detected at a Physical Access Control System?
  • Which of the following is an asset mentioned in CIP-002 R1 to be considered during categorization?
  • What is required as part of the process under CIP-002 R2.2?
  • What is one of the responsibilities under the Access Management Program?
  • What is required regarding security patches as part of a baseline configuration under CIP-010 R1.1?
  • What does CIP-006-6 specify regarding the physical security of BES Cyber Systems?
  • How does CIP-004 R5.3 address access to BES Cyber System Information upon termination?
  • CIP-008 R1.4 emphasizes the need for which of the following?
  • Which method is aimed at protecting information as outlined in the CIP standards?
  • What should be done if the timeframe for a mitigation plan needs to be extended?
  • What is the role of the Electricity Sector Information Sharing and Analysis Center (ES-ISAC) in the CIP standards?
  • In relation to reporting Cyber Security Incidents, which of the following is true?
  • What process is required for managing configuration changes, per CIP-010?
  • How frequently must the identifications in Requirement R1 be reviewed according to CIP-002 R2.1?
  • Under CIP-008 R3.1, what is the timeframe for documenting lessons learned after an incident response plan test?
  • Within how many days must a recovery plan be updated if there is a change affecting its execution per Requirement R3.2?
  • Which aspect of the Cyber Security Incident response plan is emphasized in CIP-008 R2.2?
  • What does CIP-009-6 focus on in terms of Cyber Security?
  • What must be done with events logged at the BES Cyber System level?
  • What action does CIP-004 R5.5 require regarding shared accounts after a termination?
  • According to CIP-008 R3, what should each Responsible Entity do with their Cyber Security Incident response plans?
  • What standard does CIP-004 R4.2 ensure regarding individuals with active access?
  • What is emphasized regarding access permissions in CIP-005 R1.3?
  • What does the term "defined ESP" refer to in CIP-005 R1.1?
  • What is the purpose of issuing alarms in response to unauthorized access?
  • What is a primary element of a Visitor Control Program as stated in CIP-006 R2?
  • What is emphasized by the Access Revocation requirements in CIP-004?
  • What is the main focus of CIP-007 R1?
  • What is required under CIP-008 R1.3 concerning Cyber Security Incident response?
  • What must the cyber security plans for low impact BES Cyber Systems include according to CIP-003 R2?
  • What key activity is involved in CIP-007 R2.1?
  • What is a key component of CIP-004 R4.1 concerning access authorization?
  • What does CIP-009 R2.2 specifically state should be tested at least once every 15 calendar months?
  • What is the time frame for updating the baseline configuration after a change is completed?
  • Which of the following actions is required to enforce authentication of user access?
  • What does CIP-005 R1.1 state about Cyber Assets connected to a network?
  • Which of the following parameters must be enforced for password-only authentication according to CIP-007 R5.5?
  • What type of entities are required to implement the processes outlined in CIP-011?
  • What method can be used to prevent unauthorized access to Transient Cyber Assets?
  • What must be documented after conducting vulnerability assessments?
  • Which of the following is a requirement for methods used to deter malicious code?
  • Which training component is NOT included in the Cyber Security Training Program requirements?
  • According to Requirement R3.1, how many days after a recovery plan test must lessons learned be documented?
  • According to CIP-005-5, what is critical for managing electronic security?
  • Who is responsible for the logging of visitor entry and exit?
  • What does CIP-002 R1.3 specifically require regarding low impact BES Cyber Systems?
  • Which action is NOT required under CIP-006 according to the document's physical security requirements?
  • What is the expected action regarding access after a reassignment, as per CIP-004 R5.2?
  • What is required at least once every 15 calendar months as per CIP-003 R1?
  • How often should the Physical Access Control System be maintained and tested?
  • How frequently should the baseline configuration be monitored for changes?
  • What should be included in a mitigation plan regarding security patches?
  • According to CIP-004 R3.5, what is required for individuals with electronic or unescorted access?
  • CIP-008 R3.2 requires updates to the response plan when which of the following occurs?
  • CIP-009 aims to ensure recovery plans are tested how often?
  • What does the CIP standard require regarding Removable Media?
  • Under the Cyber Security Training Program, what is required regarding training content?
  • CIP-008 R1 relates to which aspect of Cyber Security Incident response?
  • According to CIP-007 R3, what is the primary purpose of the requirement?
  • What does CIP-007 R1.1 specifically address regarding network ports?
  • What is the primary focus of CIP-002-5.1?
  • Which of the following is a requirement for the Access Revocation aspect of CIP-004?
  • CIP-009 R2.1 requires testing of recovery plans by which of the following methods?
  • When is training completion required prior to granting access to Cyber Assets?
  • Prior to making a change that deviates from the existing baseline configuration, what should be determined?
  • Which of the following processes is critical in CIP-007 to prevent unauthorized access?
  • What action must be taken before disposing of Cyber Assets containing BES Cyber System Information?
  • According to the CIP standards, what must Responsible Entities control?
  • How often should the security awareness program reinforce cybersecurity practices?
  • What is the primary objective of establishing processes under CIP-008 R1.1?
  • What information must be included in the manual or automated logging of visitor entry?
  • What is the purpose of conducting a criminal history records check in personnel risk assessment?
  • What is the required action for applicable patches identified after an evaluation completion?
  • What does CIP-006 R1.3 recommend where technically feasible?
  • What is the objective of the Electronic Security Perimeter as outlined in CIP-005?
  • How should Responsible Entities manage Transient Cyber Assets?
  • Which cyber security controls should be considered before changes are implemented?
  • What is required of each Responsible Entity under CIP-010 R1?
  • What does CIP-009 R1.2 specifically require in regards to recovery plans?
  • How often must recovery plans be tested through an operational exercise according to Requirement R2.3?
  • According to CIP-006 R1.4, what should be monitored to detect unauthorized access?
  • Which component must be utilized for Interactive Remote Access Management according to CIP-005 R2?
  • What is a primary requirement for Responsible Entities in managing BES Cyber Asset reuse and disposal?
  • Which of the following actions is necessary when a Cyber Security Incident is determined to be reportable?
  • What security measure is critical for individuals with visitor access?
  • How often must Cyber Security Incident response plans be tested according to CIP-008 R2.1?
  • What circumstances allow for exceptions to the event log retention requirement?
  • What is the required action when terminating an individual's access according to CIP-004?
  • What should each Responsible Entity do regarding Transient Cyber Assets?
  • When is it necessary to generate alerts for security events?
  • CIP-009 R3 addresses the maintenance of recovery plans. What is one of the main aspects it covers?
  • According to CIP-009 R2, how often must recovery plans be implemented and tested?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy