Access Control & Perimeter Security Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control & Perimeter Security flashcards as text
An operator must perform emergency maintenance on a PLC at 2 AM with no time to follow normal change management. Which access control approach best balances security and safety?
Answer: Use a 'break-glass' emergency account with full logging and mandatory post-incident review
Break-glass procedures provide emergency privileged access through a controlled, fully audited mechanism while preserving accountability and triggering mandatory review after the incident.
Which network segmentation approach provides the STRONGEST isolation between ICS levels in the Purdue Model?
Answer: Physical separation with firewall-controlled conduits at each level boundary
Physical separation enforced by dedicated firewalls at each Purdue level boundary provides defense-in-depth, ensuring that a breach at one level cannot directly propagate without crossing a controlled inspection point.
A vendor requires persistent VPN access to monitor a turbine control system. What is the MOST secure way to grant this access?
Answer: Provide a jump server in the DMZ with the vendor's access scoped to specific assets and time windows
A jump server in the DMZ with least-privilege, time-limited, and asset-scoped access enforces the principle of least privilege while keeping vendor traffic isolated from the broader OT network.
What is the purpose of an 'Electronic Access Point' (EAP) as defined in NERC CIP-005?
Answer: Any point of access into an Electronic Security Perimeter that must be controlled and monitored
An EAP is any routable communication path crossing the ESP boundary, and CIP-005 requires that each EAP be controlled, logged, and protected with appropriate access management.
Physical perimeter security for ICS sites should include which element specifically recommended by ICS security frameworks?
Answer: Two-person integrity (TPI) rules for access to critical control areas
Two-person integrity requires that no single individual can access critical control areas alone, reducing insider threat risk and preventing unauthorized unwitnessed actions on critical systems.
Which protocol vulnerability makes Modbus-based ICS networks particularly susceptible to unauthorized command injection?
Answer: Modbus has no native authentication or authorization mechanisms
Modbus was designed in 1979 for isolated serial networks and has no built-in authentication, meaning any device on the network segment can send valid commands to a Modbus slave device.
When designing firewall rules for an ICS ESP, which rule-base philosophy is mandated by NERC CIP and recommended by ICS security frameworks?
Answer: Default-deny with explicit allow rules for required communications only
Default-deny (implicit deny all, explicit allow required) ensures that only pre-approved, documented communication paths are permitted across the ESP boundary, minimizing the attack surface.