
GIAC Response and Industrial Defense
Domain 1Objective 3
Monitoring in an ICS Environment GRID Practice Questions (Page 8)
Part of the ICS Security Operations domain, which makes up ~54% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~27–43 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 36–40
- 36
Which of the following is a common open-source tool used for passive ICS network monitoring?
Select an answer first - 37
A hospital's building management system (BMS) is monitored by the IT security team, but the facilities team is responsible for the HVAC equipment. The monitoring system generates an alert for a suspected malware infection on a BMS controller. The IT team wants to quarantine the controller, but the facilities team says that would disrupt the operating room's temperature control. What is the most appropriate response?
Select an answer first - 38
Why is passive monitoring often preferred over active monitoring in an ICS environment?
Select an answer first - 39
A manufacturing plant's SOC receives an alert about a suspicious Modbus command from an unknown IP. The on-call analyst is unfamiliar with OT protocols. What is the most appropriate first response?
Select an answer first - 40
What is a primary challenge when monitoring legacy ICS protocols?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.