← All ICS Flashcard Decks

Report Writing & Documentation Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Report Writing & Documentation flashcards as text
  1. What is the key difference between a vulnerability report and a penetration test report in the ICS context?

    Answer: Vulnerability reports identify weaknesses without exploitation; penetration test reports document successful exploitation attempts and their impact

    Vulnerability reports catalog identified weaknesses, while penetration test reports describe how vulnerabilities were exploited to demonstrate real-world impact.

  2. A red team discovers a path from the corporate IT network to the ICS historian. How should this finding be prioritized in the report?

    Answer: Critical or high priority because IT-to-OT network paths can enable attackers to pivot into operational systems

    IT-to-OT lateral movement paths represent a critical attack vector because they can allow adversaries to reach and disrupt operational systems.

  3. Which element MUST appear in every ICS security report to ensure traceability?

    Answer: Report version number, date, author, and approval signatures

    Version, date, authorship, and approval signatures establish traceability and accountability for every formal security report.

  4. In NERC CIP compliance documentation, what does an 'evidence submission' typically include?

    Answer: Screenshots, configuration exports, log extracts, and policy documents that demonstrate compliance with specific requirements

    NERC CIP evidence submissions must include concrete artifacts—configurations, logs, screenshots, policies—that directly demonstrate each compliance requirement is met.

  5. When documenting a corrective action plan (CAP) for an ICS finding, which component is most critical?

    Answer: Specific remediation steps, responsible owner, and target completion date

    Effective CAPs specify what will be done, who is responsible, and by when, enabling tracking and accountability for remediation.

  6. Why is it important to document 'scope limitations' in an ICS security assessment report?

    Answer: To inform stakeholders of assets or areas that were not evaluated, ensuring they understand gaps in coverage

    Scope limitations inform decision-makers about assessment gaps so they can take additional steps to address unassessed risks.

  7. An ICS analyst notices a Modbus device was accessed by an unauthorized IP during an incident. How should this be documented in the incident report?

    Answer: Record the source IP, destination IP, timestamp, protocol, and action taken, citing log evidence

    Incident documentation must capture all network-level details with supporting evidence to enable investigation, remediation, and potential legal action.