ICS Cheat Sheet 2026

The 30 highest-yield ICS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

75 questions
120 min time limit
70.00% to pass
  1. ISA/IEC 62443-3-3 Security Level 2 requires protection against which threat actor category? Intentional violation using simple means by an entity with low motivation
  2. Which report type would BEST communicate recurring patch management gaps across multiple ICS sites to senior leadership? A trend analysis report showing patch compliance rates over time with risk context
  3. What distinguishes a 'passive infrared' (PIR) sensor from an 'active infrared' sensor in ICS perimeter protection? PIR sensors detect emitted body heat; active sensors transmit and receive IR beams
  4. What is the primary purpose of a demilitarized zone (DMZ) in an ICS network architecture? To host historian servers accessible from both OT and IT networks
  5. During forensic evidence collection after an ICS incident, why is it important to document the chain of custody? To preserve evidence integrity for potential legal proceedings or regulatory reporting
  6. Which threat actor group is historically associated with the CRASHOVERRIDE/Industroyer malware targeting electric grid ICS? Sandworm (Russia)
  7. How should security incidents be handled? Following an established incident response plan with documentation
  8. Which federal regulation requires cybersecurity programs for pipeline facilities, including ICS/SCADA systems? TSA Pipeline Security Directives
  9. Why is documentation critical in compliance efforts? Supports audits and accountability
  10. Under the NIST SP 800-53 control family, which control family is MOST directly applicable to ICS physical access to control rooms? Physical and Environmental Protection (PE)
  11. Which factor is most important when determining treatment frequency? Evidence-based clinical guidelines and patient response
  12. What is the PRIMARY security purpose of installing anti-ram bollards at the entrance of a critical ICS facility? Stopping vehicle-borne improvised explosive device (VBIED) or ram-raid attacks
  13. An ICS facility uses wireless sensors for remote area monitoring. Which security control is MOST critical to implement for these devices? Mutual authentication and encrypted communications between sensors and the gateway
  14. After containing an ICS cyber incident, what is the NEXT phase in the incident response lifecycle? Eradication
  15. What is the impact of denial-of-service (DoS) attacks on ICS? Loss of system availability
  16. When designing firewall rules for an ICS ESP, which rule-base philosophy is mandated by NERC CIP and recommended by ICS security frameworks? Default-deny with explicit allow rules for required communications only
  17. What is the function of a 'dead man' alarm in a remote ICS field site? Triggers when a field technician fails to check in within a defined interval
  18. How should a Industrial Control Systems Security professional handle situations beyond their expertise? Refer to a qualified specialist and communicate transparently with the client
  19. Which framework provides a common language for managing cybersecurity risk? NIST Cybersecurity Framework
  20. How should treatment protocols be modified for patients with comorbidities? Adjust parameters based on individual risk factors and contraindications
  21. What is the primary purpose of maintaining accurate professional documentation? To create a legal record of services and support continuity of care
  22. What is the recommended retention period guidance for ICS security incident records under NERC CIP standards? 3 years
  23. What is the significance of professional networking in the Industrial Control Systems Security field? It facilitates knowledge exchange, referrals, and collaborative problem-solving
  24. Which attack technique specifically targets ICS monitoring systems to make operators believe a process is running normally while malicious activity occurs? False data injection (FDI) attack
  25. In ICS environments, what is the recommended approach when a vendor-issued patch cannot be applied immediately to a critical control system? Apply compensating controls such as enhanced monitoring and network restrictions
  26. Which standard focuses specifically on control system cybersecurity? ISA/IEC 62443
  27. An ICS organization must notify the Department of Homeland Security (DHS) CISA about a significant cyber incident within 72 hours under which regulation? CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
  28. What is the primary security risk of connecting an IP surveillance camera directly to an ICS control network without segmentation? Cameras can serve as pivot points for attackers to reach control systems
  29. In OT security, which property is typically prioritized above the traditional IT security triad? Availability
  30. During an ICS vulnerability assessment, a scanner detects an open port 102 on a device. What protocol and associated risk should the analyst investigate? S7comm — susceptibility to Siemens PLC manipulation
Turn these facts into recall:
Was this helpful?