
GIAC Response and Industrial Defense
Domain 2Objective 2
Threat Hunting and Analysis in an ICS Environment GRID Practice Questions (Page 8)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
9concepts
Questions 36–40
- 36
During a hunt for a suspected rootkit on an HMI, the team needs to analyze the HMI's memory for hidden processes and kernel modifications. Which tool is most appropriate for this task?
Select an answer first - 37
Which of the following is an example of a deviation from a baseline that might indicate a threat in an ICS process?
Select an answer first - 38
A team is establishing a baseline for a wastewater treatment plant's SCADA network. They have collected network traffic for two weeks during normal operations. What is the most important consideration when using this baseline for anomaly detection?
Select an answer first - 39
In a Modbus TCP packet, which field is most important for identifying the specific device being addressed?
Select an answer first - 40
Which data source would provide the most direct evidence of unauthorized changes to a PLC's logic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.