ICS Emergency Response Procedures 3 — Questions and Answers
Question 1: What is the MAIN reason ICS emergency response exercises should include physical process scenarios, not just IT scenarios?
- To satisfy OSHA compliance requirements
- Because ICS incidents can have physical consequences that require coordinated cyber-physical response (Correct answer)
- To train IT staff on industrial equipment operation
- Because IT tools cannot detect ICS-specific threats
Correct answer: Because ICS incidents can have physical consequences that require coordinated cyber-physical response
ICS cyber incidents can cause physical harm to people, equipment, and the environment, so exercises must address the convergence of cyber and physical response.
Question 2: During forensic evidence collection after an ICS incident, why is it important to document the chain of custody?
- To ensure management can review all findings
- To preserve evidence integrity for potential legal proceedings or regulatory reporting (Correct answer)
- To allow vendors to repair equipment faster
- To satisfy patch management requirements
Correct answer: To preserve evidence integrity for potential legal proceedings or regulatory reporting
Chain of custody documentation ensures evidence was collected, handled, and stored properly, making it admissible in legal or regulatory proceedings.
Question 3: Which of the following is a key difference between IT incident response and ICS incident response?
- ICS incidents never require law enforcement notification
- ICS response must prioritize safety and process continuity, not just data confidentiality (Correct answer)
- IT incident response always takes longer than ICS response
- ICS systems cannot be forensically analyzed
Correct answer: ICS response must prioritize safety and process continuity, not just data confidentiality
Unlike IT environments where confidentiality is paramount, ICS incident response must prioritize personnel safety and maintaining critical process operations.
Question 4: What is a 'tabletop exercise' in the context of ICS emergency response?
- A physical inspection of control system hardware
- A discussion-based simulation where responders walk through an incident scenario verbally (Correct answer)
- A live-fire penetration test of ICS systems
- A review of network diagrams on a conference table
Correct answer: A discussion-based simulation where responders walk through an incident scenario verbally
A tabletop exercise is a facilitated, discussion-based activity where response team members verbally walk through their actions for a given emergency scenario.
Question 5: When an ICS vendor's remote support connection is suspected as the entry point for an attack, what is the FIRST response action?
- Contact the vendor to investigate on their end
- Terminate or block the vendor's remote access connection immediately (Correct answer)
- Preserve the connection for forensic analysis
- Notify the vendor's competitors about the vulnerability
Correct answer: Terminate or block the vendor's remote access connection immediately
Immediately blocking the suspected malicious access vector stops ongoing attacker activity and prevents further compromise before investigation continues.
Question 6: Which NIST publication provides guidance specifically relevant to ICS/SCADA incident response?
- NIST SP 800-53
- NIST SP 800-82 (Correct answer)
- NIST SP 800-61
- NIST SP 800-171
Correct answer: NIST SP 800-82
NIST SP 800-82 'Guide to Industrial Control Systems Security' provides ICS-specific security guidance including incident response considerations.
Question 7: What is the purpose of maintaining a 'golden image' or known-good backup of ICS software configurations?
- To test new features before deployment
- To enable rapid restoration of systems to a verified secure state after an incident (Correct answer)
- To share configurations with vendors for support
- To satisfy software licensing requirements
Correct answer: To enable rapid restoration of systems to a verified secure state after an incident
Known-good configuration backups allow rapid and confident restoration of ICS systems to a trusted state after malware removal or system compromise.
What is the MAIN reason ICS emergency response exercises should include physical process scenarios, not just IT scenarios?