โ† All ICS Flashcard Decks

Emergency Response Procedures Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Emergency Response Procedures flashcards as text
  1. What is the primary purpose of conducting a 'lessons learned' review after an ICS security incident?

    Answer: To identify gaps in response capabilities and improve future incident handling

    Lessons learned reviews identify what worked, what failed, and what needs improvement so that response capabilities and prevention measures are strengthened for future incidents.

  2. Why should ICS emergency response procedures explicitly address the scenario of GPS timing signal spoofing?

    Answer: Because many ICS components rely on GPS timing for synchronization, and spoofing can disrupt time-sensitive control operations

    GPS timing is used by many ICS components (e.g., protection relays, SCADA timestamps) and spoofing can cause synchronization failures leading to control system errors.

  3. Which regulatory framework requires critical infrastructure owners to report cybersecurity incidents within a specific timeframe?

    Answer: CISA's CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)

    CIRCIA mandates that covered critical infrastructure entities report significant cybersecurity incidents to CISA within 72 hours of discovery.

  4. During an ICS incident, a responder discovers that the historian server has been exfiltrating process data for 6 months. What type of attack does this indicate?

    Answer: An Advanced Persistent Threat (APT) with long-term unauthorized access and data exfiltration

    Long-term unauthorized access with covert data exfiltration over months is characteristic of APT activity, which requires extensive forensic investigation to fully scope.

  5. What is the significance of 'air-gap jumping' malware (like Stuxnet) in the context of ICS emergency response planning?

    Answer: It demonstrates that removable media and supply chain vectors can compromise even physically isolated ICS networks, requiring media controls in response plans

    Air-gap jumping malware shows that physically isolated networks can be compromised via USB drives and supply chain, so emergency response plans must account for these vectors.

  6. In ICS environments, what does 'LOTOS' (Loss of Technology Only Shutdown) refer to in emergency response?

    Answer: An emergency stop triggered by loss of operator visibility

    LOTOS refers to shutting down a process because of technology (control system) failure when the physical safety systems themselves are still operational and functional.

  7. What is the recommended approach for testing ICS incident response plans without risking production system disruption?

    Answer: Use a dedicated ICS test environment or simulation platform that mirrors the production environment

    A dedicated test environment that mirrors production allows technical validation of response procedures without risking disruption to live industrial processes.