ICS Communication & Conflict Resolution 2 — Questions and Answers
Question 1: During an ICS security incident, the operations team insists on maintaining production while the security team wants to isolate affected systems. What is the BEST approach to resolve this conflict?
- Convene a joint risk assessment with both teams to evaluate production impact versus security exposure (Correct answer)
- Always defer to the operations team since uptime is the primary ICS objective
- Escalate immediately to legal counsel to determine liability
- Allow the security team to isolate systems without operations team input
Correct answer: Convene a joint risk assessment with both teams to evaluate production impact versus security exposure
A joint risk assessment ensures both operational continuity and security concerns are weighed before a decision is made.
Question 2: Which communication protocol is commonly used for SCADA systems to transmit data between field devices and control centers in legacy ICS environments?
- Modbus (Correct answer)
- HTTPS
- SMTP
- OAuth 2.0
Correct answer: Modbus
Modbus is one of the oldest and most widely used serial communication protocols in legacy SCADA and ICS environments.
Question 3: An ICS security analyst disagrees with a vendor's recommended patch schedule for a PLC. What is the MOST appropriate first step?
- Document the concern and request a formal technical review meeting with the vendor (Correct answer)
- Immediately apply patches on the analyst's own authority
- Ignore the vendor's recommendation and follow the analyst's preferred timeline
- File a complaint with regulatory bodies before discussing with the vendor
Correct answer: Document the concern and request a formal technical review meeting with the vendor
Requesting a formal technical review ensures the concern is documented and addressed through proper channels.
Question 4: In the context of ICS security communications, what does the principle of 'need-to-know' primarily govern?
- Restricting sensitive system information to personnel with a justified operational or security role (Correct answer)
- Ensuring all employees receive the same security briefings
- Mandating that all ICS network diagrams be publicly posted
- Requiring vendors to share all proprietary system details with operators
Correct answer: Restricting sensitive system information to personnel with a justified operational or security role
Need-to-know limits access to sensitive ICS information only to those whose roles require it, reducing insider threat risk.
Question 5: When a conflict arises between IT security policies and OT operational requirements in an ICS environment, which framework is most commonly referenced to find a balanced resolution?
- IEC 62443 (Correct answer)
- PCI-DSS
- ISO 27001 alone
- HIPAA
Correct answer: IEC 62443
IEC 62443 is specifically designed to address cybersecurity in industrial automation and control systems, bridging IT/OT concerns.
Question 6: A plant manager rejects an ICS security team's recommendation to segment the control network, citing cost. Which communication strategy is MOST effective for the security team?
- Present a business risk analysis quantifying potential downtime and liability costs of a breach (Correct answer)
- Threaten to escalate to regulators if the manager refuses
- Accept the decision without further discussion
- Implement segmentation without approval and inform management afterward
Correct answer: Present a business risk analysis quantifying potential downtime and liability costs of a breach
Translating security needs into financial and operational risk terms is the most persuasive approach for decision-makers focused on costs.
Question 7: Which of the following BEST describes 'out-of-band' communication in ICS incident response?
- Using a separate, dedicated communication channel not connected to the compromised network (Correct answer)
- Sending alerts via the SCADA HMI to all operators
- Broadcasting incident details over the corporate email system
- Posting incident updates on the public company website
Correct answer: Using a separate, dedicated communication channel not connected to the compromised network
Out-of-band communication uses a channel isolated from the affected network to ensure communication integrity during an incident.
During an ICS security incident, the operations team insists on maintaining production while the security team wants to isolate affected systems.
What is the BEST approach to resolve this conflict?