
GIAC Response and Industrial Defense
Domain 2Objective 2
Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 2)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
9concepts
Questions 6–10
- 6
What is the primary goal of threat hunting in an ICS environment?
Select an answer first - 7
Which of the following is an example of an ICS-specific indicator of compromise (IOC) that might be included in a threat intelligence feed?
Select an answer first - 8
An ICS security analyst is conducting a hunt for signs of a known ransomware family that affects Windows-based HMIs. The analyst has access to Wireshark, YARA, and a memory analysis tool. Which technique would be most effective for detecting the ransomware if it is already running on an HMI?
Select an answer first - 9
A hunt team is investigating a suspected unauthorized change to a safety PLC in a refinery. The PLC is running and cannot be stopped. Which data source is most appropriate to determine if the logic has been changed?
Select an answer first - 10
When analyzing a PLC for signs of compromise, which of the following is most indicative of a potential attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.