โ† All ICS Flashcard Decks

Access Control & Perimeter Security Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control & Perimeter Security flashcards as text
  1. An ICS engineer proposes encrypting all OT network traffic to protect against eavesdropping. What is the PRIMARY operational concern with this approach?

    Answer: Encrypted traffic prevents passive network monitoring tools (IDS/anomaly detection) from inspecting payloads

    Encrypting OT traffic blinds passive IDS and anomaly detection tools that rely on deep packet inspection, potentially eliminating a critical detection layer unless decryption inspection points are deployed.

  2. Which of the following BEST describes the 'least privilege' principle as applied to ICS operator accounts?

    Answer: Each operator account should have only the minimum permissions required to perform their specific job function

    Least privilege limits the blast radius of a compromised or misused account by ensuring operators can only access and control the specific assets their role requires.

  3. A new ICS site has cellular modems attached directly to RTUs for remote monitoring. Which security risk does this configuration create?

    Answer: Direct cellular-to-RTU connections bypass the site's established security perimeter entirely

    Modems attached directly to RTUs create out-of-band pathways that circumvent firewalls, intrusion detection systems, and all other controls established at the official electronic security perimeter.

  4. Under NERC CIP-005 R2, what must organizations implement for all Interactive Remote Access into the ESP?

    Answer: Encryption and multi-factor authentication for all interactive remote access sessions

    CIP-005 R2 mandates that all Interactive Remote Access to BES Cyber Systems use encryption for the communication session and multi-factor authentication to establish the session.

  5. What is the function of an 'Intermediate System' as defined in NERC CIP-005 for managing remote access?

    Answer: A jump host or bastion server through which all remote access is routed, providing a monitored, controlled point of entry

    An Intermediate System acts as a required gateway for all remote access, ensuring that remote users never connect directly to BES Cyber Systems and all sessions are logged and inspectable.

  6. Which compensating control is MOST effective when a legacy DCS controller cannot be patched and must remain network-connected?

    Answer: Applying virtual patching via an ICS-aware IPS positioned in front of the legacy device

    An ICS-aware IPS can detect and block exploit attempts targeting known vulnerabilities in legacy devices, providing virtual patching without requiring changes to the device itself.

  7. In ICS security, what does 'defense in depth' mean when applied to access control and perimeter security?

    Answer: Layering multiple independent security controls so that failure of any single control does not result in a breach

    Defense in depth in ICS applies multiple overlapping controls (physical barriers, network segmentation, authentication, monitoring) so that an attacker must defeat all layers to reach critical assets.