ICS Communication & Conflict Resolution 3 — Questions and Answers
Question 1: An ICS engineer notices a technician bypassing a safety interlock to speed up production. The technician outranks the engineer. What should the engineer do FIRST?
- Document the bypass and report it through the established safety reporting chain immediately (Correct answer)
- Confront the technician publicly on the plant floor
- Wait to see if an incident occurs before reporting
- Accept the technician's decision since they hold higher rank
Correct answer: Document the bypass and report it through the established safety reporting chain immediately
Safety interlock bypasses must be reported immediately regardless of hierarchy, as they create immediate risk to life and systems.
Question 2: Which type of communication is MOST critical to establish before an ICS cybersecurity tabletop exercise?
- Clear roles, responsibilities, and escalation paths for all participants (Correct answer)
- Social media handles for real-time public updates
- Vendor sales contacts for emergency procurement
- Personal mobile numbers of all staff below supervisor level
Correct answer: Clear roles, responsibilities, and escalation paths for all participants
Defining roles and escalation paths before the exercise ensures participants can practice realistic, structured incident response communication.
Question 3: In ICS security, 'alarm fatigue' is a communication problem that occurs when:
- Operators receive so many alerts that critical alarms are ignored or missed (Correct answer)
- Alarms are transmitted too slowly over legacy serial protocols
- Security teams fail to configure any alarms in the SIEM
- Physical alarms are louder than required by safety regulations
Correct answer: Operators receive so many alerts that critical alarms are ignored or missed
Alarm fatigue desensitizes operators to alerts, increasing the risk that a genuine security or safety event goes unaddressed.
Question 4: When communicating ICS vulnerability findings to executive leadership, what format is MOST appropriate?
- An executive summary emphasizing business risk, impact, and recommended actions (Correct answer)
- A raw packet capture log with full technical detail
- A verbal briefing with no written documentation
- A vendor datasheet for the affected equipment
Correct answer: An executive summary emphasizing business risk, impact, and recommended actions
Executive leadership needs business-focused summaries rather than technical details to make informed decisions.
Question 5: A conflict between a remote site operator and a central ICS security team regarding a firewall rule change is BEST resolved by:
- Engaging a change control board with representatives from both operations and security (Correct answer)
- Letting the site operator implement their preferred rule since they are local
- Having the central security team override the operator without discussion
- Deferring all firewall changes until the next annual audit
Correct answer: Engaging a change control board with representatives from both operations and security
A change control board provides a neutral, structured forum to evaluate technical and operational trade-offs collaboratively.
Question 6: Which BEST describes the purpose of a 'read-back' or 'repeat-back' procedure in ICS operational communication?
- To confirm that a command or instruction was received and understood correctly (Correct answer)
- To document all voice communications for legal purposes
- To replace written procedures in high-pressure situations
- To allow operators to override supervisors without documentation
Correct answer: To confirm that a command or instruction was received and understood correctly
Read-back procedures reduce miscommunication errors by requiring the receiver to repeat critical instructions back to the sender for confirmation.
Question 7: During an ICS security assessment, a consultant discovers a critical vulnerability but the site contact asks them not to report it to management. What should the consultant do?
- Report the vulnerability according to the agreed-upon scope and disclosure terms of the engagement (Correct answer)
- Honor the site contact's request to preserve the business relationship
- Publicly disclose the vulnerability immediately without further discussion
- Only report it if a second vulnerability is found during the same visit
Correct answer: Report the vulnerability according to the agreed-upon scope and disclosure terms of the engagement
Security consultants are bound by their engagement scope and ethical obligations to report findings through agreed channels, regardless of on-site pressure.
An ICS engineer notices a technician bypassing a safety interlock to speed up production.
The technician outranks the engineer.
What should the engineer do FIRST?