โ† All ICS Flashcard Decks

Emergency Response Procedures Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Emergency Response Procedures flashcards as text
  1. During an ICS security incident, what is the PRIMARY purpose of an Incident Response Plan (IRP)?

    Answer: To provide structured steps for detecting, containing, and recovering from incidents

    An IRP provides a structured, pre-defined set of procedures to detect, contain, eradicate, and recover from security incidents in a consistent and timely manner.

  2. Which containment strategy is MOST appropriate when an ICS operator workstation is suspected of malware infection during active production?

    Answer: Isolate the workstation from the network while maintaining manual process control

    Network isolation of the suspected workstation limits malware spread while allowing manual control to maintain safety and production continuity.

  3. In ICS emergency response, what does the term 'safe state' refer to?

    Answer: A pre-defined operational condition where the physical process poses minimal hazard

    A safe state is a pre-engineered operational condition designed to minimize hazard to personnel, equipment, and the environment during an emergency.

  4. When should ICS operators switch from automated control to manual control during a cyber incident?

    Answer: When automated systems are confirmed compromised and manual control can maintain safety

    Switching to manual control is warranted when automated systems are compromised and human operators can safely maintain process control to prevent harm.

  5. What is the role of Out-of-Band (OOB) communications during an ICS cyber incident?

    Answer: To provide a communication channel that is independent of potentially compromised networks

    OOB communications (e.g., landlines, satellite phones) allow responders to coordinate without relying on networks that may be compromised.

  6. Which document should define who has the authority to order a controlled shutdown of an ICS during a security emergency?

    Answer: The Incident Response Plan or Emergency Response Procedures

    The IRP or ERP should explicitly define roles, responsibilities, and authority chains including who can authorize emergency shutdowns.

  7. After containing an ICS cyber incident, what is the NEXT phase in the incident response lifecycle?

    Answer: Eradication

    Following containment, the eradication phase focuses on removing the threat (malware, attacker access, vulnerabilities) from the environment before recovery begins.