
GIAC Response and Industrial Defense
Domain 2Objective 1
Incident Response in an ICS Environment GRID Practice Questions (Page 7)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 31–35
- 31
During an incident at a hydroelectric dam, analysts detect that an attacker has gained access to the supervisory control system and is sending commands to open a spillway gate. Operators need to maintain water levels. What is the BEST containment action?
Select an answer first - 32
After a ransomware attack on a water utility, the recovery team must restore the SCADA system. They have a backup from three days ago, but the backup may contain the malware's dormant payload. The vendor offers a clean baseline image, but it is from six months ago and lacks recent configuration changes. What is the BEST recovery approach?
Select an answer first - 33
In the incident response lifecycle, which phase involves reviewing the incident handling process to identify what went well and what could be improved?
Select an answer first - 34
Which phase of the incident response lifecycle focuses on establishing procedures, training personnel, and deploying tools before an incident occurs?
Select an answer first - 35
Why is forensic evidence collection in ICS environments challenging due to proprietary protocols?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.