TSI Cybersecurity in Transportation Networks 2 — Questions and Answers
Question 1: Which of the following best describes a supply chain cyberattack targeting transportation systems?
- Hacking a transportation agency's social media accounts
- Compromising third-party software or hardware before it reaches the transportation agency (Correct answer)
- Flooding a website with excessive traffic
- Stealing employee login credentials via email
Correct answer: Compromising third-party software or hardware before it reaches the transportation agency
A supply chain attack involves inserting malicious code or hardware into products used by the target organization before delivery, bypassing direct security controls.
Question 2: What is the principle of 'least privilege' as applied to transportation cybersecurity?
- Granting users the maximum permissions needed for any future task
- Providing users and systems only the access required to perform their specific job functions (Correct answer)
- Allowing all staff to access all systems during emergencies
- Restricting access only to the IT department
Correct answer: Providing users and systems only the access required to perform their specific job functions
Least privilege limits user and system access to only what is necessary for their role, reducing the attack surface and limiting damage if credentials are compromised.
Question 3: Under the TSA's cybersecurity directives for surface transportation, operators must report significant cybersecurity incidents within what timeframe?
- 72 hours
- 24 hours (Correct answer)
- 7 days
- 30 days
Correct answer: 24 hours
TSA's cybersecurity directives for surface transportation operators require reporting of significant cybersecurity incidents to CISA within 24 hours of identification.
Question 4: What does multi-factor authentication (MFA) add to cybersecurity in transportation control systems?
- It replaces the need for passwords entirely
- It requires users to verify identity through two or more independent factors before granting access (Correct answer)
- It encrypts all data transmitted across the network
- It monitors network traffic for suspicious activity
Correct answer: It requires users to verify identity through two or more independent factors before granting access
MFA requires a combination of something the user knows, has, or is, significantly reducing the risk of unauthorized access even if a password is stolen.
Question 5: Which organization serves as the lead civilian cybersecurity agency that transportation operators should coordinate with during a cyber incident?
- Federal Bureau of Investigation (FBI)
- Cybersecurity and Infrastructure Security Agency (CISA) (Correct answer)
- National Security Agency (NSA)
- Department of Transportation (DOT)
Correct answer: Cybersecurity and Infrastructure Security Agency (CISA)
CISA is the lead U.S. civilian cybersecurity agency responsible for coordinating incident response and providing resources to critical infrastructure sectors including transportation.
Question 6: Ransomware attacks on transportation systems are particularly dangerous primarily because:
- They are difficult to detect with antivirus software
- They can encrypt operational systems and halt critical transportation services until a ransom is paid (Correct answer)
- They only affect passenger data and not operations
- They are typically carried out by nation-state actors exclusively
Correct answer: They can encrypt operational systems and halt critical transportation services until a ransom is paid
Ransomware can encrypt critical operational systems such as dispatch, ticketing, and control networks, forcing transportation services to halt until systems are restored or a ransom is paid.
Question 7: What is the purpose of a cybersecurity incident response plan (IRP) for transportation agencies?
- To prevent all cyberattacks from occurring
- To establish pre-defined procedures for detecting, containing, eradicating, and recovering from cyber incidents (Correct answer)
- To train employees in software development
- To audit financial records following a breach
Correct answer: To establish pre-defined procedures for detecting, containing, eradicating, and recovering from cyber incidents
An IRP provides structured, pre-defined steps for responding to cyber incidents to minimize disruption, preserve evidence, and restore normal operations as quickly as possible.
Which of the following best describes a supply chain cyberattack targeting transportation systems?