← All ICS Flashcard Decks

Mixed Deck — All ICS Topics Flashcards

100 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All ICS Topics flashcards as text
  1. In ICS incident response, what does 'Defense in Depth' mean when applied to emergency procedures?

    Answer: Layering multiple response capabilities so that failure of one does not leave the system unprotected

    Defense in depth in emergency response means multiple overlapping response measures ensure that if one control fails, others still protect the system and people.

  2. Which protocol is commonly used for communication in SCADA systems?

    Answer: Modbus

    Modbus is one of the oldest and most widely used serial communication protocols in SCADA (Supervisory Control and Data Acquisition) systems and other industrial control applications. It allows devices like PLCs, RTUs, and sensors to communicate with each other and with supervisory systems. Despite its age, Modbus remains prevalent due to its simplicity and widespread adoption, though it lacks inherent security features.

  3. Which NIST document provides a risk management framework (RMF) process applicable to federal ICS and OT systems?

    Answer: NIST SP 800-37

    NIST SP 800-37 defines the Risk Management Framework (RMF) — a six-step process (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) applied to federal information systems including OT.

  4. Why is regular security training important for all staff?

    Answer: Employees are often the weakest link in security and training reduces human error

    Regular security training reduces human error, the most common cause of security breaches, by keeping all staff aware of current threats and proper procedures.

  5. During an ICS security assessment, auditors find that substation doors use padlocks from multiple vendors with varying key grades. What is the BEST remediation?

    Answer: Replace all padlocks with a standardized high-security keyed-alike system

    Standardizing to high-security, keyed-alike padlocks reduces key management complexity and ensures uniform resistance to picking and forced entry.

  6. Why is staying current with industry developments important for Industrial Control Systems Security professionals?

    Answer: To provide the best possible service using current knowledge and practices

    Staying current ensures professionals provide the best possible service by incorporating the latest knowledge, techniques, and regulatory requirements.

  7. A field technician and an ICS cybersecurity analyst disagree about whether a legacy RTU should be replaced or patched. Which conflict resolution approach is MOST constructive?

    Answer: Conduct a formal risk assessment comparing residual risk of patching vs. replacement cost and timeline

    A formal risk assessment provides objective data to guide decisions involving technical and financial trade-offs.

  8. The IEC 62443 standard series addresses security for which type of systems?

    Answer: Industrial Automation and Control Systems (IACS)

    IEC 62443 is the international standard series specifically developed for Industrial Automation and Control Systems (IACS) security.

  9. In IEC 62443, what term describes the maximum tolerable level of security risk for a given system or zone?

    Answer: Target Security Level (SL-T)

    The Target Security Level (SL-T) in IEC 62443 defines the desired security level that a zone or conduit must achieve based on risk assessment.

  10. Which of the following BEST illustrates a 'two-person integrity' (TPI) communication control in an ICS context?

    Answer: Requiring two authorized personnel to both confirm and log any critical control system command

    TPI requires two people to independently confirm critical actions, preventing both errors and insider threats in high-consequence ICS operations.

  11. What network monitoring technique passively captures ICS protocol traffic to build a baseline of normal device behavior?

    Answer: Passive network traffic analysis

    Passive network traffic analysis captures and inspects OT protocol traffic without generating any packets that could disrupt sensitive ICS devices.

  12. During an ICS vulnerability assessment, a scanner detects an open port 102 on a device. What protocol and associated risk should the analyst investigate?

    Answer: S7comm — susceptibility to Siemens PLC manipulation

    Port 102 is used by S7comm, the Siemens S7 PLC communication protocol, and represents a significant risk as it can be exploited to read/write memory, start/stop PLCs, and was the protocol targeted by Stuxnet.

  13. Which threat actor group is historically associated with the CRASHOVERRIDE/Industroyer malware targeting electric grid ICS?

    Answer: Sandworm (Russia)

    Sandworm, a Russian state-sponsored threat group, deployed CRASHOVERRIDE/Industroyer against Ukraine's power grid in December 2016, causing a blackout by manipulating substation ICS equipment.

  14. During an ICS security assessment, a consultant discovers a critical vulnerability but the site contact asks them not to report it to management. What should the consultant do?

    Answer: Report the vulnerability according to the agreed-upon scope and disclosure terms of the engagement

    Security consultants are bound by their engagement scope and ethical obligations to report findings through agreed channels, regardless of on-site pressure.

  15. An ICS engineer proposes encrypting all OT network traffic to protect against eavesdropping. What is the PRIMARY operational concern with this approach?

    Answer: Encrypted traffic prevents passive network monitoring tools (IDS/anomaly detection) from inspecting payloads

    Encrypting OT traffic blinds passive IDS and anomaly detection tools that rely on deep packet inspection, potentially eliminating a critical detection layer unless decryption inspection points are deployed.

  16. What is a 'watering hole' attack as it applies to ICS threat vectors?

    Answer: Compromising websites frequently visited by ICS engineers to deliver malware

    A watering hole attack compromises websites that ICS personnel commonly visit, using drive-by downloads to infect their workstations and gain ICS network access.

  17. An ICS facility wants to detect unauthorized excavation near buried pipeline control cables. Which technology is BEST suited for this?

    Answer: Fiber-optic distributed acoustic sensing (DAS)

    Distributed acoustic sensing detects vibration and mechanical disturbance along buried fiber-optic cable, alerting to unauthorized digging.

  18. Which vulnerability category is most prevalent in legacy ICS environments due to the age of the installed equipment?

    Answer: Unpatched software and firmware

    Legacy ICS devices often run outdated firmware and OS versions that cannot be patched without disrupting operations, leaving known vulnerabilities unaddressed.

  19. A private security officer at a natural gas compressor station may use deadly force ONLY when:

    Answer: The officer reasonably believes there is an imminent threat of death or serious bodily injury

    Deadly force is legally justified only when the officer has a reasonable belief of imminent threat of death or serious bodily injury, consistent with state use-of-force statutes.

  20. Which of the following is an example of 'constructive conflict' in an ICS security program?

    Answer: A red team challenging assumptions in an ICS defense architecture to identify weaknesses

    Constructive conflict, like red team exercises, challenges existing assumptions to improve security outcomes rather than creating dysfunction.