
GIAC Response and Industrial Defense
Domain 2Objective 1
Incident Response in an ICS Environment GRID Practice Questions (Page 2)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 6–10
- 6
After a cyber incident at a mining operation, the lessons-learned review identifies that the incident response team lacked real-time visibility into the OT network. Which improvement is MOST effective to address this gap?
Select an answer first - 7
A security analyst at a nuclear facility is reviewing network logs and sees a series of Modbus read requests from an unknown IP address to a PLC controlling cooling water. The requests are querying the PLC's register map. What does this activity most likely indicate?
Select an answer first - 8
Which detection technique is commonly used to identify anomalies in ICS network traffic?
Select an answer first - 9
During a major ICS incident, the incident response team is receiving conflicting information from operations and IT. Operations wants to keep the process running, while IT wants to isolate systems to prevent spread. The incident commander needs to make a decision. Which factor should be given the highest priority?
Select an answer first - 10
When triaging a potential ICS incident, which factor is most important to prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.