Security Cybersecurity Threats and Vulnerabilities Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Cybersecurity Threats and Vulnerabilities flashcards as text
What is the significance of the Purdue Model (ISA-95) in ICS threat analysis?
Answer: It provides a hierarchical reference model used to identify trust boundaries and attack paths between IT and OT
The Purdue Model defines hierarchical levels of ICS architecture, helping security teams identify where threats can traverse from enterprise IT networks down to field devices.
Which threat involves an attacker capturing and later retransmitting legitimate ICS protocol messages to replay authorized commands?
Answer: Replay attack
Replay attacks record valid ICS commands and retransmit them later to manipulate process equipment, exploiting protocols that lack message timestamps or sequence numbers.
Which of the following BEST describes an Advanced Persistent Threat (APT) actor's typical behavior in an ICS environment?
Answer: Long-term stealthy presence focused on reconnaissance and positioning for future impact
APT actors in ICS environments typically prioritize stealth and persistence over speed, spending months or years mapping systems before executing a disruptive payload.
What is the role of a 'historian' server in ICS networks, and why is it a high-value target?
Answer: It aggregates real-time process data and bridges IT and OT networks, making it a pivot point and intelligence source
Historian servers collect and store operational process data while often having connectivity to both OT and IT networks, making them valuable for espionage and as a lateral movement pivot.
When an ICS vendor releases a security advisory for a critical vulnerability but a patch cannot be applied immediately, what is the MOST appropriate compensating control?
Answer: Implement network segmentation and monitoring rules to detect exploitation attempts
Network segmentation limits exposure while enhanced monitoring provides detection capability, balancing operational continuity with risk reduction when immediate patching is not feasible.
What does 'fuzzing' mean in the context of discovering ICS vulnerabilities?
Answer: Sending malformed or random inputs to ICS devices or protocols to discover crashes or unexpected behavior
Fuzzing systematically sends invalid, unexpected, or random data to ICS devices or protocol stacks to uncover vulnerabilities such as buffer overflows or improper input handling.
Which scenario BEST represents a 'living off the land' attack in an ICS environment?
Answer: Using legitimate built-in tools like PowerShell, WMI, or native engineering software to move laterally and execute actions
Living-off-the-land attacks use pre-existing legitimate tools and system features, making them harder to detect because they don't rely on custom malware signatures.