Threat Assessment & Risk Analysis Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Assessment & Risk Analysis flashcards as text
A power utility uses the ISA/IEC 62443 standard for risk assessment. What term does this standard use to describe the combination of likelihood and consequence that defines overall risk?
Answer: Security Level Target (SL-T)
ISA/IEC 62443 uses 'Security Level Target (SL-T)' to define the required level of protection, derived from the risk assessment of the consequences of a security breach combined with likelihood factors.
Which of the following best describes a 'chained attack' in the context of ICS threat scenarios?
Answer: A sequence of exploits where each step enables the next to reach an ICS target
A chained attack is a sequence of exploitation steps where gaining access or capabilities in one stage enables the next stage, commonly seen in ICS breaches where attackers pivot from IT to OT networks.
During an ICS vulnerability assessment, a scanner detects an open port 102 on a device. What protocol and associated risk should the analyst investigate?
Answer: S7comm — susceptibility to Siemens PLC manipulation
Port 102 is used by S7comm, the Siemens S7 PLC communication protocol, and represents a significant risk as it can be exploited to read/write memory, start/stop PLCs, and was the protocol targeted by Stuxnet.
A risk analyst is prioritizing remediation efforts. Which framework explicitly provides a method to calculate risk priority using threat, vulnerability, and asset value inputs for ICS?
Answer: DHS CSET Risk Assessment
The DHS Cyber Security Evaluation Tool (CSET) provides ICS-specific risk assessment methodology that explicitly incorporates threat, vulnerability, and asset value to produce prioritized risk results.
What is the significance of 'consequence isolation' as a risk reduction strategy in ICS environments?
Answer: Designing systems so a cyber incident in one zone cannot trigger safety consequences in another
Consequence isolation means designing ICS architectures so that a compromise in one system or zone cannot propagate to trigger physical safety consequences in adjacent or dependent systems.
Which threat actor group is historically associated with the CRASHOVERRIDE/Industroyer malware targeting electric grid ICS?
Answer: Sandworm (Russia)
Sandworm, a Russian state-sponsored threat group, deployed CRASHOVERRIDE/Industroyer against Ukraine's power grid in December 2016, causing a blackout by manipulating substation ICS equipment.
In a semi-quantitative ICS risk assessment, an analyst assigns a likelihood score of 3 (on a 1-5 scale) and a consequence score of 5. A proposed control reduces consequence to 3. What is the percentage reduction in risk score?
Answer: 40%
Original risk = 3×5=15; residual risk = 3×3=9; reduction = (15-9)/15 = 6/15 = 40%, illustrating how consequence reduction controls can significantly lower overall risk.