โ† All ICS Flashcard Decks

Security Cybersecurity Threats and Vulnerabilities Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Cybersecurity Threats and Vulnerabilities flashcards as text
  1. What is the primary risk of using remote desktop tools (RDP, VNC) for ICS remote access without additional controls?

    Answer: Exposure of full desktop environments with weak or no multi-factor authentication

    RDP/VNC sessions without MFA and proper access controls provide attackers who obtain credentials with complete interactive access to ICS workstations.

  2. Which MITRE ATT&CK for ICS tactic describes an adversary's attempt to learn about the target ICS environment after initial access?

    Answer: Discovery

    The Discovery tactic in MITRE ATT&CK for ICS covers techniques adversaries use to enumerate network topology, devices, and process information after gaining access.

  3. What is 'logic bomb' placement in ICS context?

    Answer: Inserting malicious code that activates under specific process conditions

    A logic bomb is malicious code hidden within legitimate ICS programs that executes only when predefined conditions (e.g., a specific date or process state) are met.

  4. Supply chain attacks on ICS environments most commonly involve which vector?

    Answer: Compromised software updates or hardware components from trusted vendors

    Supply chain attacks embed malware or backdoors in legitimate vendor software updates or hardware, leveraging the trusted relationship between vendor and asset owner.

  5. What defines a 'zero-day' vulnerability in the context of ICS security?

    Answer: An unknown vulnerability with no available patch at the time of exploitation

    A zero-day vulnerability is unknown to the vendor or public, giving defenders zero days to patch before exploitation occurs.

  6. An ICS operator notices that a field device is sending commands it was not programmed to execute. This BEST describes which type of threat?

    Answer: Unauthorized command injection

    Unauthorized command injection occurs when an attacker sends illegitimate control commands to field devices, bypassing normal operator authorization.

  7. Which technique do ICS-targeted ransomware operators increasingly use to maximize pressure on victims?

    Answer: Exfiltrating operational data before encryption to threaten public release

    Double extortion ransomware steals sensitive operational and business data before encrypting systems, threatening to publish it if the ransom is not paid.