Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Response and Industrial Defense

Domain 1Objective 2

Detection in an ICS Environment GRID Practice Questions (Page 2)

Part of the ICS Security Operations domain, which makes up ~54% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~27–43 in this domain), expect 7–11 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
10concepts

Questions 6–10

  1. 6application · medium

    A chemical plant has never performed a formal ICS asset inventory. The security team is deploying an active scanner to enumerate devices on the control network. The network contains legacy PLCs that are known to crash when scanned aggressively, a modern DCS with redundant controllers, and several unmanaged Ethernet switches. The team needs a complete asset list to build detection use cases. Which approach best balances safety and completeness?

    Select an answer first
  2. 7foundation · easy

    What is a key characteristic of passive network monitors used in ICS security monitoring?

    Select an answer first
  3. 8foundation · easy

    Which of the following is a specialized tool or platform commonly used for ICS security monitoring?

    Select an answer first
  4. 9expert · hard

    A nuclear power plant's security team is reviewing SIEM alerts. They see a series of Modbus writes to a turbine governor's setpoint registers from an engineering workstation. The writes are incrementing the setpoint by small amounts over several hours. The workstation is used by a contractor who is on site for a scheduled maintenance. The contractor's badge logs show they were in the control room during the writes. The plant's change management system has no record of these writes. What is the most likely scenario?

    Select an answer first
  5. 10application · medium

    A security analyst at a power utility is reviewing alerts from the SIEM. The SIEM flagged a series of Modbus TCP writes to a protective relay's setpoint registers from an engineering workstation. The writes occurred at 3:00 AM, and the workstation is not normally used at that time. The analyst also sees a separate alert for a failed login to the same workstation at 2:55 AM. Which of the following is the most appropriate next step in the incident detection workflow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.