SCADA & Industrial Protocol Security Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 SCADA & Industrial Protocol Security flashcards as text
What is 'defense in depth' as applied to ICS cybersecurity?
Answer: Applying multiple overlapping layers of security controls so that failure of one layer does not result in total compromise
Defense in depth applies multiple independent security layers — physical controls, network segmentation, authentication, monitoring — so that an attacker must defeat several barriers to cause harm.
Which NIST publication serves as the primary guide for securing Industrial Control Systems?
Answer: NIST SP 800-82
NIST SP 800-82 'Guide to Industrial Control Systems (ICS) Security' provides guidance specific to SCADA, DCS, and PLC systems, including risk management and countermeasures tailored to OT environments.
What is a 'data historian' in an ICS environment and why is it a security concern?
Answer: A time-series database server that stores process data and often bridges IT and OT zones, creating a potential attack pathway
A data historian (e.g., OSIsoft PI) stores time-series process data and is frequently connected to both the OT network (to collect data) and the IT network (to share data with business users), making it a potential pivot point for attackers.
What is the purpose of a Demilitarized Zone (DMZ) placed between an IT network and an OT network?
Answer: To create an intermediate buffer zone that controls and mediates data exchange between the IT and OT environments
An IT/OT DMZ is an intermediate network segment that allows controlled data sharing (e.g., via a data historian or jump server) without establishing direct connections between the corporate network and the control system network.
A false data injection attack against a SCADA system is best described as:
Answer: Manipulating sensor or process data transmitted to the SCADA system so operators receive false readings and make incorrect control decisions
A false data injection (FDI) attack involves an adversary intercepting and altering sensor readings or process values so the operator sees normal conditions while the actual process is in an abnormal or dangerous state.
Which international standard specifically addresses cybersecurity for Industrial Automation and Control Systems (IACS)?
Answer: IEC 62443
IEC 62443 is the international series of standards published by IEC that defines requirements and processes for implementing and maintaining cybersecurity in industrial automation and control systems.
In IEC 62443, the concept of 'security zones and conduits' refers to:
Answer: Grouping ICS assets with similar security requirements into zones and defining tightly controlled communication pathways (conduits) between those zones
IEC 62443 defines security zones as logical groupings of assets sharing common security requirements, and conduits as the communication paths between zones that must be protected and monitored to limit lateral movement.