
GIAC Response and Industrial Defense
Domain 2Objective 2
Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 7)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
9concepts
Questions 31–35
- 31
A hunt team has completed a hypothesis-driven hunt for unauthorized Modbus writes in a factory. They found no malicious activity but noticed that several HMIs have outdated firmware. What should the team include in the final report?
Select an answer first - 32
Why is documentation an important part of the threat hunting process in an ICS environment?
Select an answer first - 33
An analyst is examining Modbus TCP traffic in a manufacturing plant. The baseline shows that the HMI reads registers from a PLC every second. The analyst notices a series of write requests to a register that is normally read-only. What is the most likely explanation to investigate?
Select an answer first - 34
During a hunt for a suspected logic bomb in a manufacturing plant, the team needs to identify any unauthorized changes to PLC logic. Which data source is most likely to provide the needed evidence?
Select an answer first - 35
What is the first step in a structured threat hunting process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.