ICS Emergency Response Procedures 2 — Questions and Answers
Question 1: During an ICS security incident, what is the PRIMARY purpose of an Incident Response Plan (IRP)?
- To punish employees who caused the incident
- To provide structured steps for detecting, containing, and recovering from incidents (Correct answer)
- To document system configurations for insurance claims
- To notify vendors about product defects
Correct answer: To provide structured steps for detecting, containing, and recovering from incidents
An IRP provides a structured, pre-defined set of procedures to detect, contain, eradicate, and recover from security incidents in a consistent and timely manner.
Question 2: Which containment strategy is MOST appropriate when an ICS operator workstation is suspected of malware infection during active production?
- Immediately shut down the entire plant
- Isolate the workstation from the network while maintaining manual process control (Correct answer)
- Continue operations and investigate after the shift ends
- Reimage the workstation without preserving forensic evidence
Correct answer: Isolate the workstation from the network while maintaining manual process control
Network isolation of the suspected workstation limits malware spread while allowing manual control to maintain safety and production continuity.
Question 3: In ICS emergency response, what does the term 'safe state' refer to?
- A network segment with no external connections
- A pre-defined operational condition where the physical process poses minimal hazard (Correct answer)
- A backup SCADA server in standby mode
- An encrypted communications channel between control centers
Correct answer: A pre-defined operational condition where the physical process poses minimal hazard
A safe state is a pre-engineered operational condition designed to minimize hazard to personnel, equipment, and the environment during an emergency.
Question 4: When should ICS operators switch from automated control to manual control during a cyber incident?
- Only after executive management approves the switch
- When automated systems are confirmed compromised and manual control can maintain safety (Correct answer)
- After completing all forensic evidence collection
- Only during scheduled maintenance windows
Correct answer: When automated systems are confirmed compromised and manual control can maintain safety
Switching to manual control is warranted when automated systems are compromised and human operators can safely maintain process control to prevent harm.
Question 5: What is the role of Out-of-Band (OOB) communications during an ICS cyber incident?
- To bypass firewall rules for faster incident response
- To provide a communication channel that is independent of potentially compromised networks (Correct answer)
- To encrypt SCADA traffic during the incident
- To automatically notify regulators of the breach
Correct answer: To provide a communication channel that is independent of potentially compromised networks
OOB communications (e.g., landlines, satellite phones) allow responders to coordinate without relying on networks that may be compromised.
Question 6: Which document should define who has the authority to order a controlled shutdown of an ICS during a security emergency?
- The asset inventory spreadsheet
- The Incident Response Plan or Emergency Response Procedures (Correct answer)
- The vendor's equipment manual
- The IT department's change management policy
Correct answer: The Incident Response Plan or Emergency Response Procedures
The IRP or ERP should explicitly define roles, responsibilities, and authority chains including who can authorize emergency shutdowns.
Question 7: After containing an ICS cyber incident, what is the NEXT phase in the incident response lifecycle?
- Preparation
- Eradication (Correct answer)
- Identification
- Lessons learned
Correct answer: Eradication
Following containment, the eradication phase focuses on removing the threat (malware, attacker access, vulnerabilities) from the environment before recovery begins.
During an ICS security incident, what is the PRIMARY purpose of an Incident Response Plan (IRP)?