
GIAC Response and Industrial Defense
Domain 2Objective 3
Threat Intelligence in an ICS Environment GRID Practice Questions (Page 1)
Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 1–5
- 1
A security analyst is tuning an IDS for a power utility's control network. They receive a threat intelligence feed with a list of IP addresses and domain names associated with a recent campaign. The analyst notices that some of the IPs are used by a legitimate remote vendor for maintenance. What is the best way to handle this situation?
Select an answer first - 2
During the direction phase of the threat intelligence lifecycle, an ICS security manager defines the intelligence requirements for the next quarter. Which action best exemplifies this phase?
Select an answer first - 3
During the processing phase of the threat intelligence lifecycle, an analyst receives raw data from multiple sources, including vendor advisories and ISAC alerts. What is the primary goal of this phase?
Select an answer first - 4
Which analytical method is used to correlate seemingly unrelated indicators to identify a broader attack campaign?
Select an answer first - 5
Which type of indicator is most likely to detect an attacker who is using legitimate credentials to access an ICS workstation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.