Security Network Architecture and Protocols Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Network Architecture and Protocols flashcards as text
Which attack technique involves an adversary inserting themselves between an HMI and a PLC to intercept and modify control commands?
Answer: Man-in-the-middle (MitM) attack
A man-in-the-middle attack intercepts communications between the HMI and PLC, allowing the attacker to read or alter commands and responses.
What ICS-specific network protocol operates over serial communication and uses function codes to read/write registers on remote devices?
Answer: Modbus RTU
Modbus RTU uses serial communication with function codes (e.g., FC03 for read holding registers) to interact with PLCs and other field devices.
Which NIST publication provides a cybersecurity framework commonly referenced for ICS and critical infrastructure protection?
Answer: NIST SP 800-82
NIST SP 800-82 is the Guide to Industrial Control System Security specifically tailored for ICS environments including SCADA and DCS.
In ICS environments, what is the recommended approach when a vendor-issued patch cannot be applied immediately to a critical control system?
Answer: Apply compensating controls such as enhanced monitoring and network restrictions
Compensating controls such as tightened firewall rules, enhanced IDS monitoring, and network isolation mitigate risk when patching is operationally infeasible.
Which EtherNet/IP security feature provides authentication and encryption for industrial Ethernet devices running CIP protocol?
Answer: CIP Security using TLS/DTLS
CIP Security extends EtherNet/IP with TLS (TCP) and DTLS (UDP) to provide device authentication and encrypted communication.
What physical security control complements network segmentation to protect ICS field devices from unauthorized local access?
Answer: Locked control panel enclosures with access logging
Locked enclosures with access logging prevent unauthorized physical access to PLCs, RTUs, and other field devices that may lack network-layer authentication.
Which network protocol is used by ICS devices for automatic IP address assignment and can be exploited through rogue DHCP server attacks?
Answer: DHCP
A rogue DHCP server can assign attacker-controlled IP addresses, default gateways, or DNS servers to ICS devices, redirecting their traffic.