Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Response and Industrial Defense

Domain 2Objective 3

Threat Intelligence in an ICS Environment GRID Practice Questions (Page 7)

Part of the ICS Incident Management and Intelligence domain, which makes up ~46% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~23–37 in this domain), expect 8–12 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 31–35

  1. 31foundation · easy

    What is the primary goal of threat intelligence analysis in an ICS environment?

    Select an answer first
  2. 32expert · hard

    An ICS security manager must produce a threat intelligence report for the board of directors after a near-miss incident. The board is concerned about the financial and reputational impact. Which report structure best meets the board's needs?

    Select an answer first
  3. 33foundation · easy

    Which of the following is an example of a host-based indicator of compromise (IOC) in an ICS environment?

    Select an answer first
  4. 34expert · hard

    An ICS security team is evaluating a threat intelligence feed that provides a large number of IOCs, but many are not relevant to their OT environment. They are concerned about the operational impact of false positives. What is the most effective way to use this feed?

    Select an answer first
  5. 35foundation · easy

    Which of the following best describes the typical motivation of a hacktivist targeting an ICS environment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRID” is a trademark of its owner, used for identification only.