Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Response and Industrial Defense

Domain 2Objective 2

Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 5)

Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
9concepts

Questions 21–25

  1. 21expert · hard · select all that apply

    A security analyst is conducting a hunt for a sophisticated adversary that may have compromised an HMI and is using it as a pivot point to reach PLCs. The analyst has access to Wireshark, YARA, memory analysis tools, and the HMI's event logs. Which combination of techniques would provide the most comprehensive detection of this activity? Select all that apply.

    Select an answer first
  2. 22foundation · easy

    Which of the following is an ICS-specific data source that is commonly used for threat hunting?

    Select an answer first
  3. 23expert · hard

    A pharmaceutical plant has a well-established baseline for its batch process. During a hunt, an analyst notices that the temperature setpoint for a reactor has been changed by 0.5°C during a batch, which is within the normal variation range. However, the change occurred at 3:00 AM, which is outside the normal shift schedule. The analyst must decide whether this is a threat or a benign anomaly. What is the best approach?

    Select an answer first
  4. 24application · medium

    An analyst is reviewing a packet capture from a power utility's DNP3 network. The capture shows a master station polling a remote terminal unit (RTU) every 5 seconds, but at 02:13:45, a single unsolicited response containing a control command is sent from the RTU to the master. What is the most significant anomaly to investigate?

    Select an answer first
  5. 25application · medium

    During a hunt, an analyst discovers that a PLC's program file has been modified, but the change is not documented in the change management system. The PLC is still running the process normally. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.