โ† All ICS Flashcard Decks

Security Risk Management and Incident Response Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Risk Management and Incident Response flashcards as text
  1. When conducting a Business Impact Analysis (BIA) for an ICS facility, the Maximum Tolerable Downtime (MTD) represents:

    Answer: The longest period a business process can be unavailable before causing unacceptable harm

    MTD defines the absolute maximum time a critical process can be offline before the impact becomes catastrophic to the organization or safety.

  2. Which of the following BEST describes a qualitative risk assessment approach in ICS security?

    Answer: Using descriptive scales (low/medium/high) and expert judgment to rate likelihood and impact

    Qualitative risk assessment uses descriptive categories and expert judgment rather than precise numerical calculations, making it useful when data is limited.

  3. An ICS incident response team discovers evidence that an attacker used a legitimate vendor remote access account to enter the OT network. The IMMEDIATE containment action should be:

    Answer: Disable or revoke the compromised vendor account and block the associated access path

    Immediately disabling the compromised account and blocking the access vector stops ongoing unauthorized access and prevents further lateral movement.

  4. The Security Content Automation Protocol (SCAP) is relevant to ICS risk management because it:

    Answer: Enables standardized, automated vulnerability scanning and configuration compliance checking

    SCAP standardizes the expression of security configurations and vulnerability data, enabling automated compliance checking and vulnerability assessment in ICS environments.

  5. In risk communication for ICS environments, executive briefings on security risk should primarily emphasize:

    Answer: Business impact, operational consequences, and resource requirements for risk treatment

    Executives need to understand business impact and resource implications to make informed risk treatment decisions, not technical vulnerability details.

  6. Which of the following is a key difference between IT and ICS incident response procedures?

    Answer: ICS incidents may require coordination with safety systems and process engineers before taking containment actions

    In ICS environments, containment actions can affect physical processes, so safety engineers must be consulted before isolating systems or shutting down components.

  7. A risk register for an ICS environment should be reviewed and updated:

    Answer: Continuously, with formal reviews triggered by significant changes, new threats, or on a defined periodic basis

    Risk registers must reflect the current threat landscape and system changes, requiring both event-driven updates (new vulnerabilities, system changes) and periodic scheduled reviews.