← All ICS Flashcard Decks

Emergency Response Procedures Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Emergency Response Procedures flashcards as text
  1. In ICS incident response, what does 'Defense in Depth' mean when applied to emergency procedures?

    Answer: Layering multiple response capabilities so that failure of one does not leave the system unprotected

    Defense in depth in emergency response means multiple overlapping response measures ensure that if one control fails, others still protect the system and people.

  2. Why is it critical to notify the Information Sharing and Analysis Center (ISAC) relevant to your sector after an ICS incident?

    Answer: To share threat intelligence that can help other organizations in the sector defend against the same attack

    ISACs facilitate trusted sharing of threat intelligence between sector peers, enabling the broader community to defend against attacks seen by one organization.

  3. Which scenario BEST demonstrates the need for pre-established mutual aid agreements in ICS incident response?

    Answer: A major incident that overwhelms one utility's response capacity, requiring neighboring utilities' expertise

    Mutual aid agreements pre-establish terms for one organization to assist another during large-scale incidents that exceed the affected organization's response capacity.

  4. During recovery from an ICS incident, what is the significance of performing a 'functional test' before returning systems to full production?

    Answer: To verify that restored systems operate correctly and safely before resuming full process control

    Functional testing confirms that restored ICS components perform correctly and safely, reducing the risk of returning to production with residual issues.

  5. What is the PRIMARY concern when applying patches to ICS systems during or immediately after an incident?

    Answer: Patches may destabilize ICS systems that have not been tested in the specific operational environment

    ICS systems are often highly sensitive to changes; untested patches can cause process instability or failures, making testing and vendor consultation essential even during incident recovery.

  6. What is the function of a 'Security Operations Center' (SOC) in supporting ICS incident response?

    Answer: To provide 24/7 monitoring, detection, and initial triage of security events affecting ICS environments

    A SOC provides continuous monitoring and alerting capabilities, enabling faster detection and initial triage of security events before they escalate to full incidents.

  7. An attacker has modified ladder logic in a PLC to cause unsafe equipment behavior. What is the CORRECT emergency response sequence?

    Answer: Initiate safe shutdown, isolate the PLC, restore verified-good logic, then test before resuming operations

    Modified control logic poses immediate physical safety risk; the correct sequence is safe shutdown first, then isolation, restoration from a verified backup, and testing before resumption.