Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Response and Industrial Defense

Domain 2Objective 3

Threat Intelligence in an ICS Environment GRID Practice Questions (Page 4)

Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 16–20

  1. 16expert · hard

    An ICS security team is considering implementing a new threat intelligence feed that provides a high volume of indicators, including many that are not relevant to their environment. The team is concerned about the operational impact on their small SOC. What is the most important consideration before integrating this feed?

    Select an answer first
  2. 17application · medium

    An analyst is correlating threat intelligence with network logs and finds that a known malicious IP address has been communicating with a PLC on the control network. However, the communication pattern matches normal engineering activity. What is the most appropriate analytical conclusion?

    Select an answer first
  3. 18application · medium

    An ICS organization wants to integrate threat intelligence into its security operations. They have a SIEM and an IDS. They receive a feed of indicators from an ISAC. What is the most effective way to use this feed?

    Select an answer first
  4. 19application · medium

    An incident responder is analyzing a cyber intrusion at a power plant. The attacker used a spear-phishing email to gain initial access, then moved laterally using legitimate remote administration tools, and finally manipulated the HMI to cause a brief outage. Which threat actor profile best matches this behavior?

    Select an answer first
  5. 20application · medium

    A natural gas pipeline operator is evaluating threat intelligence sources to improve their situational awareness. They have limited staff and need timely, actionable information about threats specific to pipeline control systems. Which source should they prioritize?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.