Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Response and Industrial Defense

Domain 2Objective 2

Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 10)

Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
9concepts

Questions 46–50

  1. 46expert · hard

    A security team at a wind farm receives a threat intelligence report about a new ICS malware that uses OPC UA to communicate with controllers. The report includes a YARA rule and a list of malicious OPC UA server IPs. The team has limited time and must decide how to use this intelligence effectively. They have access to network captures and endpoint logs. What is the most efficient approach?

    Select an answer first
  2. 47expert · hard

    During a hunt on an engineering workstation, the team finds a suspicious DLL loaded into a process that communicates with an external IP. The workstation is critical for plant operations and cannot be taken offline. What is the best course of action to gather evidence while minimizing disruption?

    Select an answer first
  3. 48expert · hard

    A hunt team is investigating a suspected advanced persistent threat (APT) on a set of HMIs. They have collected memory dumps and file system images. They need to identify malware that is designed to evade signature-based detection. Which combination of techniques is most effective?

    Select an answer first
  4. 49expert · hard

    A regional water utility has a mature security program but limited staffing. They have a hypothesis that a sophisticated adversary may have established persistence in their SCADA environment. They have access to historian logs, PLC program files, and network flow data. The team must choose a hunting approach that balances thoroughness with limited resources. Which approach is most effective?

    Select an answer first
  5. 50application · medium

    A security manager at a food processing plant wants to implement threat hunting to complement their existing IDS. The manager is concerned about the impact on production. What is the most important principle to communicate to the team?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.