
GIAC Response and Industrial Defense
Domain 2Objective 2
Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 4)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
9concepts
Questions 16–20
- 16
Which ICS protocol is commonly used in electric utility SCADA systems and is characterized by its master-slave communication model?
Select an answer first - 17
An analyst is reviewing packet captures from a DNP3 network and notices that a master station is polling a remote terminal unit (RTU) at an unusually high frequency. The baseline polling interval is 5 seconds, but the capture shows polls every 200 milliseconds. What should the analyst do next?
Select an answer first - 18
During a threat hunt at a chemical plant, an analyst needs to determine whether an attacker manipulated the setpoints of a specific PLC over the past month. Which combination of data sources would provide the most reliable evidence?
Select an answer first - 19
A security team is planning a threat hunt in a natural gas pipeline environment. They have access to a commercial ICS threat intelligence feed that provides indicators of compromise (IOCs) for known malware families. What is the most effective way to use this feed in the hunt?
Select an answer first - 20
How does threat hunting in an ICS environment differ from traditional IT threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.