← All ICS Flashcard Decks

Threat Assessment & Risk Analysis Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Assessment & Risk Analysis flashcards as text
  1. In ICS environments, which threat modeling methodology is most commonly adapted to account for physical-cyber interdependencies?

    Answer: STRIDE

    STRIDE is widely adapted for ICS threat modeling because its spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege categories map naturally to both cyber and physical control system attack vectors.

  2. A risk analyst discovers that a legacy PLC has no authentication and communicates over Modbus TCP. Which risk factor most directly increases the likelihood score in a quantitative risk assessment?

    Answer: Known vulnerability with public exploit code

    A known vulnerability with publicly available exploit code dramatically increases likelihood because threat actors can weaponize it without advanced capabilities, directly elevating the probability component of the risk formula.

  3. Which document provides the foundational risk management framework specifically referenced in NIST SP 800-82 for ICS security?

    Answer: NIST SP 800-30

    NIST SP 800-30 provides the Guide for Conducting Risk Assessments and is the foundational document cited in NIST SP 800-82 for performing risk assessments in ICS environments.

  4. During a threat assessment of a water treatment SCADA system, an analyst identifies an insider with legitimate access who has expressed grievances. This threat actor is best classified as:

    Answer: Malicious insider

    An employee with authorized access who may use that access maliciously due to personal motivations is classified as a malicious insider, a particularly dangerous threat in ICS environments due to existing access and system knowledge.

  5. What is the primary purpose of a Bow-Tie analysis in ICS risk assessment?

    Answer: To visualize threat pathways, preventive barriers, and consequence mitigations simultaneously

    Bow-Tie analysis visually connects threats on the left (causes) through a central hazard event to consequences on the right, showing both preventive controls and recovery mitigations in a single diagram.

  6. An ICS risk assessment uses the formula Risk = Consequence × Likelihood. If a threat scenario has a consequence score of 4 and a likelihood score of 2, but adding a firewall reduces likelihood to 1, what is the residual risk value?

    Answer: 4

    Residual risk = Consequence × Reduced Likelihood = 4 × 1 = 4, demonstrating how a control reduces likelihood while consequence remains unchanged.

  7. Which ICS-specific threat intelligence source focuses exclusively on industrial control system vulnerabilities and advisories issued by the U.S. government?

    Answer: CISA ICS-CERT Advisories

    CISA ICS-CERT Advisories are specifically produced by the Cybersecurity and Infrastructure Security Agency to address vulnerabilities and threats targeting industrial control systems.