ISP ISP Industrial Control Systems & Critical Infrastructure Security 2 — Questions and Answers
Question 1: Presidential Policy Directive 21 (PPD-21) identifies how many critical infrastructure sectors in the United States?
- 8
- 12
- 16 (Correct answer)
- 21
Correct answer: 16
PPD-21 designates 16 critical infrastructure sectors, each with a designated Sector Risk Management Agency (SRMA) responsible for sector-specific guidance.
Question 2: Which NIST publication provides a cybersecurity framework specifically tailored for ICS and SCADA systems?
- NIST SP 800-53
- NIST SP 800-82 (Guide to ICS Security) (Correct answer)
- NIST SP 800-171
- NIST SP 800-61
Correct answer: NIST SP 800-82 (Guide to ICS Security)
NIST SP 800-82 provides specific guidance on applying security controls to industrial control systems, SCADA, and other OT environments.
Question 3: A 'unidirectional gateway' (data diode) in an OT network is BEST described as:
- A two-way firewall configured to allow only approved traffic in both directions
- A hardware device that physically allows data to flow in only one direction, preventing any reverse communication (Correct answer)
- A software-based VPN tunnel for secure OT remote access
- A backup power supply for network switches in control rooms
Correct answer: A hardware device that physically allows data to flow in only one direction, preventing any reverse communication
Data diodes enforce unidirectional data flow at the hardware level, making it physically impossible for data to travel back from the secure OT network to the IT network.
Question 4: Which threat actor type poses the GREATEST risk to critical national infrastructure due to their resources and long-term strategic objectives?
- Script kiddies using publicly available exploit tools
- Nation-state Advanced Persistent Threat (APT) groups (Correct answer)
- Opportunistic ransomware criminals targeting random organizations
- Disgruntled former employees with residual access
Correct answer: Nation-state Advanced Persistent Threat (APT) groups
Nation-state APT groups have significant resources, technical sophistication, and long-term strategic patience that makes them uniquely dangerous to critical infrastructure.
Question 5: The ISA/IEC 62443 standard series applies to:
- Personnel security clearance processes in industrial facilities
- Security for Industrial Automation and Control Systems (IACS) across the entire lifecycle (Correct answer)
- Fire suppression system design in manufacturing plants
- Physical access control for data centers
Correct answer: Security for Industrial Automation and Control Systems (IACS) across the entire lifecycle
ISA/IEC 62443 is the international standard series addressing security requirements for industrial automation and control systems from design through operation.
Question 6: When conducting a vulnerability assessment of an OT/ICS environment, which approach is PREFERRED over active network scanning?
- Running automated vulnerability scanners at maximum speed during peak production hours
- Passive network monitoring and asset inventory using non-intrusive methods to avoid disrupting real-time control processes (Correct answer)
- Physically unplugging all devices to examine them individually
- Conducting assessments only on IT systems while excluding OT networks
Correct answer: Passive network monitoring and asset inventory using non-intrusive methods to avoid disrupting real-time control processes
Active scanning can crash legacy OT devices or disrupt time-sensitive control processes, making passive monitoring the preferred approach in live OT environments.
Presidential Policy Directive 21 (PPD-21) identifies how many critical infrastructure sectors in the United States?