Surveillance & Monitoring Systems Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Surveillance & Monitoring Systems flashcards as text
Which attack technique specifically targets ICS monitoring systems to make operators believe a process is running normally while malicious activity occurs?
Answer: False data injection (FDI) attack
False data injection attacks manipulate sensor readings or HMI displays to show normal values while the actual process is being tampered with.
What is the purpose of 'change management' controls in the context of ICS surveillance and monitoring systems?
Answer: Ensuring all modifications to monitoring configurations are authorized, documented, and reversible
Change management ensures that modifications to monitoring systems are formally reviewed to prevent unauthorized changes that could create blind spots or vulnerabilities.
An ICS facility uses wireless sensors for remote area monitoring. Which security control is MOST critical to implement for these devices?
Answer: Mutual authentication and encrypted communications between sensors and the gateway
Wireless ICS sensors must use mutual authentication to prevent rogue device insertion and encryption to prevent eavesdropping or data manipulation.
Which concept describes the practice of deliberately feeding false data to an attacker's monitoring session to mislead their understanding of the ICS environment?
Answer: Deception technology / honeypot deployment
Deception technology, including honeypots and fake assets, feeds misleading information to adversaries who have breached the perimeter to slow their progress and reveal their presence.
What ICS-specific challenge makes traditional IT vulnerability scanning tools potentially dangerous to use in OT environments?
Answer: Active scanning can crash legacy ICS devices that cannot handle unexpected network probes
Many legacy ICS devices have fragile network stacks that can crash, reboot, or lose communications when subjected to the probe traffic generated by active vulnerability scanners.
When establishing a Security Operations Center (SOC) for ICS monitoring, what is the most important OT-specific capability to include beyond standard IT SOC functions?
Answer: Understanding of industrial process context to distinguish cyber anomalies from legitimate process variations
ICS SOC analysts must understand industrial processes to determine whether an anomaly represents a cyber threat or a legitimate operational event, preventing both missed alerts and false response actions.
Which ICS monitoring scenario BEST illustrates the principle of 'defense in depth' applied to surveillance systems?
Answer: Combining perimeter fencing, badge access logs, IP cameras, motion sensors, and network anomaly detection in overlapping layers
Defense in depth requires multiple independent, overlapping security layers so that failure of any single control does not compromise overall security.