최신 GRID 무료덤프 - GIAC Response and Industrial Defense (GRID)
Your organization has deployed an IDS in an ICS environment, and the system has generated an alert indicating unusual communication between a remote workstation and a programmable logic controller (PLC).
How should you proceed with investigating this issue?
How should you proceed with investigating this issue?
정답: A
Why is it difficult to deploy detection tools that perform full system scans in ICS environments?
정답: B
Your security team has received a high-priority alert from a network intrusion detection system (NIDS) monitoring an ICS environment. The alert indicates unusual outbound communication from an ICS device to an external IP address.
What steps should you take to investigate and mitigate this potential security threat?
What steps should you take to investigate and mitigate this potential security threat?
정답: C
Which of the following best describes tactical threat intelligence in the context of ICS security?
정답: B
Which of the following is a key factor when determining whether a detected anomaly is a legitimate threat?
정답: D
What is the role of event logs in monitoring ICS systems?
정답: A
In ICS environments, what is the primary advantage of using anomaly-based detection systems?
정답: C
Your threat hunting team has identified unusual outbound communication from a PLC to an unknown external IP address.
What steps should you take to investigate this anomaly?
What steps should you take to investigate this anomaly?
정답: A
A manufacturing plant that relies on ICS systems for its production line receives an alert indicating that unauthorized access was attempted on one of its programmable logic controllers (PLCs).
What should be the first steps in handling this situation using active defense principles?
What should be the first steps in handling this situation using active defense principles?
정답: D
What is the primary purpose of threat analysis in an ICS environment?
정답: C