โ† All ICS Flashcard Decks

Access Control & Perimeter Security Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control & Perimeter Security flashcards as text
  1. Which authentication mechanism is considered most appropriate for machine-to-machine communications between ICS devices where human interaction is not feasible?

    Answer: Certificate-based mutual TLS authentication

    Mutual TLS with X.509 certificates allows devices to authenticate each other cryptographically without human interaction, and certificate lifecycle management can be automated.

  2. A security assessment reveals that a substation's serial SCADA links bypass the established firewall perimeter. What is the FIRST corrective action?

    Answer: Identify whether the links are within scope of the ESP and apply compensating controls such as protocol-aware serial gateways

    Serial links crossing the ESP boundary require compensating controls such as protocol-aware gateways, data diodes, or encryption, and must be documented and assessed against the applicable standard (e.g., NERC CIP-005).

  3. What is the primary purpose of network whitelisting (application whitelisting at the network layer) in ICS perimeter defense?

    Answer: Permitting only pre-approved source/destination/port combinations and denying all other traffic

    Network whitelisting enforces the principle of least communication privilege by allowing only known-good traffic flows and automatically blocking anything outside the defined baseline.

  4. ISA/IEC 62443-3-3 Security Level 2 requires protection against which threat actor category?

    Answer: Intentional violation using simple means by an entity with low motivation

    SL 2 targets protection against intentional violations using low sophistication means by attackers with low resources and motivation, such as casual hackers or disgruntled low-skill insiders.

  5. Why is it problematic to use the same Active Directory (AD) domain for both IT and OT user authentication in industrial environments?

    Answer: A compromise of the IT AD infrastructure could grant attackers authenticated access to OT systems

    Sharing an AD domain means a credential theft or DC compromise on the IT side can be leveraged to authenticate to OT systems, breaking the security zone boundary.

  6. Which physical access control measure is specifically designed to prevent 'tailgating' into secured ICS control rooms?

    Answer: Mantrap (airlock) vestibule requiring individual authentication for each person

    A mantrap uses two interlocked doors where only one can open at a time, physically preventing a second person from entering behind an authenticated user without presenting their own credentials.

  7. What does the concept of 'conduit' mean in ISA/IEC 62443 zone and conduit modeling?

    Answer: A logical grouping of communication channels sharing the same security characteristics between zones

    A conduit is the logical communication path between two or more zones, and ISA/IEC 62443 requires that conduits be identified, documented, and secured with appropriate controls matching the lower security level of the zones they connect.