ISP ISP Industrial Control Systems & Critical Infrastructure Security 1 — Questions and Answers
Question 1: Which U.S. government agency is the primary authority for protecting critical infrastructure cybersecurity and coordinates sector-specific agencies?
- Federal Bureau of Investigation (FBI)
- Cybersecurity and Infrastructure Security Agency (CISA) (Correct answer)
- National Security Agency (NSA)
- Department of Justice (DOJ)
Correct answer: Cybersecurity and Infrastructure Security Agency (CISA)
CISA leads national efforts to understand, manage, and reduce risk to cyber and physical infrastructure across the 16 critical infrastructure sectors.
Question 2: An Industrial Control System (ICS) SCADA network differs from a traditional IT network primarily because:
- SCADA networks require faster internet connectivity
- ICS/SCADA systems control physical processes with real-time requirements where downtime or errors can have safety consequences (Correct answer)
- SCADA systems are always connected to the public internet for remote monitoring
- ICS networks exclusively use wireless communication protocols
Correct answer: ICS/SCADA systems control physical processes with real-time requirements where downtime or errors can have safety consequences
ICS/SCADA systems manage physical processes—pipelines, power grids, manufacturing lines—where cyber failures can directly cause physical harm or safety incidents.
Question 3: The Purdue Model (Industrial Automation and Control Systems reference architecture) is PRIMARILY used to:
- Design marketing campaigns for industrial products
- Define network segmentation zones and security boundaries between IT and OT systems (Correct answer)
- Calculate production output targets for manufacturing plants
- Assess employee ergonomics in industrial settings
Correct answer: Define network segmentation zones and security boundaries between IT and OT systems
The Purdue Model provides a hierarchical framework for segmenting industrial networks into zones from the enterprise level down to field devices, enabling security boundary definition.
Question 4: Which of the following is a unique security challenge in Operational Technology (OT) environments compared to IT?
- OT systems are updated more frequently than IT systems
- Many OT devices have 20-30 year lifecycles and cannot accept security patches without disrupting operations (Correct answer)
- OT systems have stronger built-in authentication than IT systems
- OT environments have smaller attack surfaces than enterprise IT networks
Correct answer: Many OT devices have 20-30 year lifecycles and cannot accept security patches without disrupting operations
Legacy OT devices were designed for longevity and reliability, not security, making patching difficult or impossible without operational impact.
Question 5: A 'DMZ' (Demilitarized Zone) between IT and OT networks is PRIMARILY designed to:
- Increase data transfer speeds between enterprise and control networks
- Provide a controlled buffer zone where data can be exchanged between IT and OT without direct connectivity (Correct answer)
- Allow unrestricted internet access to control systems for remote monitoring
- Replace the need for firewalls in industrial environments
Correct answer: Provide a controlled buffer zone where data can be exchanged between IT and OT without direct connectivity
An OT DMZ allows necessary data flows between IT and OT while preventing direct connectivity that could enable lateral movement of attackers.
Question 6: Stuxnet is historically significant in ICS security because it demonstrated that:
- Nuclear power plants are immune to cyberattack due to physical isolation
- Air-gapped industrial control systems can be compromised through physical media, causing real-world physical damage (Correct answer)
- Cyber operations against industrial systems require nation-state resources and are therefore rare
- SCADA vulnerabilities are only exploitable from within the facility network
Correct answer: Air-gapped industrial control systems can be compromised through physical media, causing real-world physical damage
Stuxnet proved that air gaps can be crossed via infected USB drives and that malware can cause physical destruction to industrial equipment.
Which U.S. government agency is the primary authority for protecting critical infrastructure cybersecurity and coordinates sector-specific agencies?