ATP Physical & Cyber Security Integration 3 — Questions and Answers
Question 1: A water treatment facility classifies its operational technology (OT) network as critical infrastructure. Which approach BEST represents converged physical-cyber resilience for this environment?
- Air-gapped OT network with physically controlled jump servers and logged USB usage for data transfer (Correct answer)
- Directly connecting OT devices to the corporate IT network to simplify monitoring
- Encrypting all PLC-to-HMI communications using TLS 1.3 without physical access controls
- Allowing remote vendor access via shared VPN credentials to reduce operational costs
Correct answer: Air-gapped OT network with physically controlled jump servers and logged USB usage for data transfer
Air-gapping OT networks with tightly controlled, monitored physical access points reduces both cyber and insider-threat attack surfaces.
Question 2: Video surveillance footage is subpoenaed as evidence after a physical breach that also involved data exfiltration. Which chain-of-custody principle is MOST critical when handling this digital evidence?
- Maintaining a documented, unbroken log of who accessed, copied, and transferred the footage from collection to courtroom (Correct answer)
- Immediately sharing footage with all incident response team members via email
- Deleting the original footage after making three backup copies
- Converting footage to a lower resolution to reduce file size before submission
Correct answer: Maintaining a documented, unbroken log of who accessed, copied, and transferred the footage from collection to courtroom
An unbroken chain of custody documents every person who handled the evidence, preserving its integrity and admissibility in legal proceedings.
Question 3: A company's security policy requires all visitors to be escorted and wear temporary badges. A visitor is discovered in a restricted server room unescorted with their badge obscured. Which term describes this type of insider threat scenario?
- Unintentional or intentional policy violation enabling physical reconnaissance or data exfiltration (Correct answer)
- Social engineering via phishing
- A shoulder-surfing incident
- A logic bomb deployment event
Correct answer: Unintentional or intentional policy violation enabling physical reconnaissance or data exfiltration
An unescorted visitor in a restricted area may represent a policy violation enabling physical reconnaissance or theft of data/hardware.
Question 4: Which encryption standard is recommended for protecting data on removable media that may leave a physically secure facility?
- AES-256 in XTS mode (Correct answer)
- DES with a 56-bit key
- MD5 with a salt
- ROT-13 encoding
Correct answer: AES-256 in XTS mode
AES-256 in XTS mode (IEEE P1619) is the industry standard for full-disk and removable-media encryption due to its strength and sector-level diffusion.
Question 5: A Security Operations Center (SOC) analyst notices that a card reader alarm triggered at 2:47 AM correlates with an outbound data transfer spike on the SIEM at 2:49 AM. This is an example of:
- Physical-cyber event correlation detecting a coordinated insider attack or breach (Correct answer)
- A coincidental false positive in both systems
- A misconfigured SIEM threshold producing duplicate alerts
- Normal scheduled backup activity triggering both sensors
Correct answer: Physical-cyber event correlation detecting a coordinated insider attack or breach
Temporal correlation between a physical access event and a network anomaly strongly suggests a coordinated attack combining physical and cyber vectors.
Question 6: Under HSPD-12 / FIPS 201, what is the primary purpose of the Personal Identity Verification (PIV) card for federal employees?
- To provide a single interoperable credential for both physical access to buildings and logical access to IT systems (Correct answer)
- To replace social security numbers for payroll processing
- To serve solely as a visual identification badge without electronic functionality
- To store encrypted email certificates only for classified communications
Correct answer: To provide a single interoperable credential for both physical access to buildings and logical access to IT systems
HSPD-12 mandates PIV cards as a common interoperable credential enabling both physical access control and PKI-based logical access across federal agencies.
Question 7: An attacker cuts the fiber connecting a building's IP camera system to the security server just before breaching the facility. Which resilience design would BEST mitigate this tactic?
- Cameras with onboard SD card storage and cellular backup uplink that continue recording and alerting independently (Correct answer)
- Higher resolution cameras with better night vision
- Adding more cameras to the same fiber ring
- Storing footage only in the cloud with no local backup
Correct answer: Cameras with onboard SD card storage and cellular backup uplink that continue recording and alerting independently
Local onboard storage combined with an independent cellular uplink ensures continuous recording and alerting even when primary network connectivity is severed.
A water treatment facility classifies its operational technology (OT) network as critical infrastructure.
Which approach BEST represents converged physical-cyber resilience for this environment?