Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Response and Industrial Defense

Domain 2Objective 2

Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 3)

Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
9concepts

Questions 11–15

  1. 11expert · hard

    A security team is integrating a threat intelligence feed into their ICS hunting program. The feed contains IOCs for a malware family that targets engineering workstations. The team has limited resources and must decide how to prioritize hunting activities. Which approach is most effective?

    Select an answer first
  2. 12expert · hard

    After a threat hunt at a nuclear facility, the team has identified a suspicious file on an engineering workstation that matches a known ICS malware signature. The file is not in the approved software list, and the workstation is used for safety system configuration. The team must decide how to report and remediate. What is the most appropriate action?

    Select an answer first
  3. 13application · medium

    A security analyst is reviewing Modbus TCP traffic and notices that a client is sending read requests to a PLC for register addresses that are not used by the process. The requests are coming from an IP address that is not in the list of known HMIs. What should the analyst do?

    Select an answer first
  4. 14foundation · easy

    Which threat hunting methodology starts with a specific hypothesis about how an attacker might operate in the environment?

    Select an answer first
  5. 15expert · hard

    A power utility's SOC has observed an increase in DNP3 traffic to a substation RTU. The baseline shows that the RTU is polled every 10 seconds, but for the past hour, polls have been arriving every 2 seconds from a different source IP. The team must determine if this is malicious. Which approach best balances the need for investigation with operational safety?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.