
GIAC Response and Industrial Defense
Domain 1Objective 2
Detection in an ICS Environment GRID Practice Questions (Page 5)
Part of the ICS Security Operations domain, which makes up ~54% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~27–43 in this domain), expect 7–11 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
Questions 21–25
- 21
A refinery's security operations center (SOC) receives an alert from the SIEM: a PLC on the crude unit has been writing to a different PLC's memory area using Modbus function code 16 (Write Multiple Registers). The source PLC is not configured to communicate with the target PLC. The SOC analyst is following the incident detection workflow. What is the first step the analyst should take?
Select an answer first - 22
Which of the following is an example of a behavioral deviation that might be detected in an ICS environment?
Select an answer first - 23
A chemical plant uses Modbus TCP between a DCS and several PLCs. The security team has a passive monitor and has established a baseline. The baseline shows that the DCS polls each PLC every 1 second with function code 3, and writes setpoints with function code 6 during shift changes. One day, the monitor detects a series of function code 16 (Write Multiple Registers) commands from the DCS to a PLC that controls a reactor temperature. The writes are changing multiple registers at once, and the values are within the normal operating range. The DCS logs show no corresponding operator action. What is the most appropriate response?
Select an answer first - 24
A water utility's SOC receives an alert from the SIEM: a PLC on the distribution network has been writing to a different PLC's memory area using Modbus function code 16 (Write Multiple Registers). The source PLC is not configured to communicate with the target PLC. The SOC analyst is following the incident detection workflow. The analyst has verified the alert and confirmed it is not a false positive. What is the next step in the workflow?
Select an answer first - 25
A pharmaceutical plant has deployed a new ICS intrusion detection system (IDS). The IDS is generating a high volume of alerts, most of which are false positives. The alerts are triggered by normal operational events, such as batch start/stop commands and temperature setpoint changes. The security team wants to reduce false positives without missing genuine threats. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.